CVE-2020-5421

In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N
pivotalCNA
8.7 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
vmwarespring_framework
𝑥
< 4.3.29
vmwarespring_framework
5.0.0 ≤
𝑥
< 5.0.19
vmwarespring_framework
5.1.0 ≤
𝑥
< 5.1.18
vmwarespring_framework
5.2.0 ≤
𝑥
< 5.2.9
oraclecommerce_guided_search
11.3.2
oraclecommunications_brm
11.3.0.9
oraclecommunications_brm
12.0.0.3
oraclecommunications_design_studio
7.3.4
oraclecommunications_design_studio
7.3.5
oraclecommunications_design_studio
7.4.0
oraclecommunications_session_report_manager
8.2.1 ≤
𝑥
≤ 8.2.2.1
oraclecommunications_unified_inventory_management
7.3.4
oraclecommunications_unified_inventory_management
7.3.5
oracleendeca_information_discovery_integrator
3.2.0
oracleenterprise_data_quality
12.2.1.3.0
oracleenterprise_data_quality
12.2.1.4.0
oraclefinancial_services_analytical_applications_infrastructure
8.0.6 ≤
𝑥
≤ 8.1.0
oracleflexcube_private_banking
12.0.0
oracleflexcube_private_banking
12.1.0
oraclefusion_middleware
12.2.1.3.0
oraclefusion_middleware
12.2.1.4.0
oraclegoldengate_application_adapters
19.1.0.0.0
oraclehealthcare_master_person_index
4.0.2.5
oraclehyperion_infrastructure_technology
11.1.2.4
oracleinsurance_policy_administration
11.1.0 ≤
𝑥
≤ 11.3.0
oracleinsurance_policy_administration
10.2
oracleinsurance_policy_administration
10.2.4
oracleinsurance_policy_administration
11.0.2
oracleinsurance_rules_palette
11.1.0 ≤
𝑥
≤ 11.3.0
oracleinsurance_rules_palette
10.2.0
oracleinsurance_rules_palette
10.2.4
oracleinsurance_rules_palette
11.0.2
oraclemysql_enterprise_monitor
𝑥
≤ 8.0.22
oraclemysql_enterprise_monitor
8.0.23
oracleprimavera_gateway
16.2.0 ≤
𝑥
≤ 16.2.11
oracleprimavera_gateway
17.12.0 ≤
𝑥
≤ 17.12.9
oracleprimavera_gateway
18.8.0 ≤
𝑥
≤ 18.8.10
oracleprimavera_gateway
19.12.0 ≤
𝑥
≤ 19.12.10
oracleprimavera_p6_enterprise_project_portfolio_management
16.1.0 ≤
𝑥
≤ 16.2.20
oracleprimavera_p6_enterprise_project_portfolio_management
17.1.0 ≤
𝑥
≤ 17.12.19
oracleprimavera_p6_enterprise_project_portfolio_management
18.1.0 ≤
𝑥
≤ 18.8.21
oracleprimavera_p6_enterprise_project_portfolio_management
19.12.0 ≤
𝑥
≤ 19.12.10
oracleretail_assortment_planning
16.0.3.0
oracleretail_bulk_data_integration
16.0.3.0
oracleretail_customer_engagement
16.0 ≤
𝑥
≤ 19.0
oracleretail_customer_management_and_segmentation_foundation
16.0 ≤
𝑥
≤ 19.0
oracleretail_financial_integration
14.1.3
oracleretail_financial_integration
15.0.3
oracleretail_financial_integration
16.0.3
oracleretail_integration_bus
14.1.3
oracleretail_integration_bus
15.0.3
oracleretail_integration_bus
16.0.3
oracleretail_invoice_matching
14.0
oracleretail_invoice_matching
14.1
oracleretail_merchandising_system
16.0.3
oracleretail_order_broker
15.0
oracleretail_order_broker
16.0
oracleretail_predictive_application_server
14.1
oracleretail_returns_management
14.1
oracleretail_service_backbone
14.1.3
oracleretail_service_backbone
15.0.3
oracleretail_service_backbone
16.0.3
oracleretail_xstore_point_of_service
15.0.4
oracleretail_xstore_point_of_service
16.0.6
oracleretail_xstore_point_of_service
17.0.4
oracleretail_xstore_point_of_service
18.0.3
oracleretail_xstore_point_of_service
19.0.2
oraclestoragetek_acsls
8.5.1
oraclestoragetek_tape_analytics_sw_tool
2.3
oracleweblogic_server
10.3.6.0.0
oracleweblogic_server
12.1.3.0.0
oracleweblogic_server
12.2.1.3.0
oracleweblogic_server
12.2.1.4.0
oracleweblogic_server
14.1.1.0.0
netapponcommand_insight
-
netappsnap_creator_framework
-
netappsnapcenter
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libspring-java
bullseye
4.3.30-1
fixed
sid
4.3.30-2
fixed
trixie
4.3.30-2
fixed
bookworm
4.3.30-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libspring-java
noble
needs-triage
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
needs-triage
impish
ignored
hirsute
ignored
groovy
ignored
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
needs-triage
References