CVE-2021-22096
28.10.2021, 16:15
In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.Enginsight
Vendor | Product | Version |
---|---|---|
vmware | spring_framework | 5.2.0 ≤ 𝑥 ≤ 5.2.17 |
vmware | spring_framework | 5.3.0 ≤ 𝑥 ≤ 5.3.10 |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
netapp | management_services_for_element_software_and_netapp_hci | - |
netapp | metrocluster_tiebreaker | - |
netapp | snap_creator_framework | - |
netapp | snapcenter | - |
oracle | communications_cloud_native_core_console | 1.9.0 |
oracle | communications_cloud_native_core_service_communication_proxy | 1.15.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References