CVE-2021-22096
28.10.2021, 16:15
In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.Enginsight
| Vendor | Product | Version |
|---|---|---|
| vmware | spring_framework | 5.2.0 ≤ 𝑥 ≤ 5.2.17 |
| vmware | spring_framework | 5.3.0 ≤ 𝑥 ≤ 5.3.10 |
| netapp | active_iq_unified_manager | - |
| netapp | active_iq_unified_manager | - |
| netapp | active_iq_unified_manager | - |
| netapp | management_services_for_element_software_and_netapp_hci | - |
| netapp | metrocluster_tiebreaker | - |
| netapp | snap_creator_framework | - |
| netapp | snapcenter | - |
| oracle | communications_cloud_native_core_console | 1.9.0 |
| oracle | communications_cloud_native_core_service_communication_proxy | 1.15.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References