MEDIUM · 5.0

CVE-2010-3700

VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attacker...

Vulnerability Description

VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
AcegisecurityAcegi-Security1.0.0
VmwareSpringsource Spring Security2.0.0
IbmWebsphere Application Server6.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-3700?

CVE-2010-3700 is a vulnerability with a CVSS score of 5.0 (MEDIUM). VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attacker...

How severe is CVE-2010-3700?

CVE-2010-3700 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-3700?

Check the references section above for vendor advisories and patch information. Affected products include: Acegisecurity Acegi-Security, Vmware Springsource Spring Security, Ibm Websphere Application Server.