CVE-2020-5421
—CVSS 3.1
6.5 medium
EPSS
11%p96
Published
()
Modified
Description
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
- Vendors
- vmwareoraclenetapp
- Products
- spring framework, commerce guided search, communications brm, communications design studio, communications session report manager, communications unified inventory management, endeca information discovery integrator, enterprise data quality, financial services analytical applications infrastructure, flexcube private banking, fusion middleware, goldengate application adapters
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.