MEDIUM · 6.5

CVE-2020-5421

In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depen...

Vulnerability Description

In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
VmwareSpring Framework< 4.3.29
OracleCommerce Guided Search11.3.2
OracleCommunications Brm11.3.0.9
OracleCommunications Design Studio7.3.4
OracleCommunications Session Report Manager>= 8.2.1, <= 8.2.2.1
OracleCommunications Unified Inventory Management7.3.4
OracleEndeca Information Discovery Integrator3.2.0
OracleEnterprise Data Quality12.2.1.3.0
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.6, <= 8.1.0
OracleFlexcube Private Banking12.0.0
OracleFusion Middleware12.2.1.3.0
OracleGoldengate Application Adapters19.1.0.0.0
OracleHealthcare Master Person Index4.0.2.5
OracleHyperion Infrastructure Technology11.1.2.4
OracleInsurance Policy Administration>= 11.1.0, <= 11.3.0
OracleInsurance Rules Palette>= 11.1.0, <= 11.3.0
OracleMysql Enterprise Monitor<= 8.0.22
OraclePrimavera Gateway>= 16.2.0, <= 16.2.11
OraclePrimavera P6 Enterprise Project Portfolio Management>= 16.1.0, <= 16.2.20
OracleRetail Assortment Planning16.0.3.0

References

FAQ

What is CVE-2020-5421?

CVE-2020-5421 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depen...

How severe is CVE-2020-5421?

CVE-2020-5421 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-5421?

Check the references section above for vendor advisories and patch information. Affected products include: Vmware Spring Framework, Oracle Commerce Guided Search, Oracle Communications Brm, Oracle Communications Design Studio, Oracle Communications Session Report Manager.