CVE-2010-1622

SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
oraclefusion_middleware
7.6.2
oraclefusion_middleware
11.1.1.6.1
oraclefusion_middleware
11.1.1.8.0
springsourcespring_framework
2.5.0
springsourcespring_framework
2.5.1
springsourcespring_framework
2.5.2
springsourcespring_framework
2.5.3
springsourcespring_framework
2.5.4
springsourcespring_framework
2.5.5
springsourcespring_framework
2.5.6
springsourcespring_framework
2.5.7
springsourcespring_framework
3.0.0
springsourcespring_framework
3.0.1
springsourcespring_framework
3.0.2
𝑥
= Vulnerable software versions