ZeroHour

CVE-2020-5421

CVSS 3.1
6.5 medium
EPSS
11%p96
Published
()
Modified
Description

In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.

Vendors
vmwareoraclenetapp
Products
spring framework, commerce guided search, communications brm, communications design studio, communications session report manager, communications unified inventory management, endeca information discovery integrator, enterprise data quality, financial services analytical applications infrastructure, flexcube private banking, fusion middleware, goldengate application adapters
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N

In the news

No ingested article mentions this CVE yet.