HIGH · 7.8

CVE-2021-22118

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a...

Vulnerability Description

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
VmwareSpring Framework>= 5.2.0, < 5.2.15
OracleCommerce Guided Search11.3.2
OracleCommunications Brm - Elastic Charging Engine12.0.0.3
OracleCommunications Cloud Native Core Binding Support Function1.9.0
OracleCommunications Cloud Native Core Policy1.14.0
OracleCommunications Cloud Native Core Security Edge Protection Proxy1.6.0
OracleCommunications Cloud Native Core Service Communication Proxy1.14.0
OracleCommunications Cloud Native Core Unified Data Repository1.14.0
OracleCommunications Diameter Intelligence Hub>= 8.0.0, <= 8.1.0
OracleCommunications Element Manager>= 8.2.0, <= 8.2.4.0
OracleCommunications Interactive Session Recorder6.4
OracleCommunications Network Integrity7.3.6
OracleCommunications Session Report Manager>= 8.0.0, <= 8.2.4.0
OracleCommunications Session Route Manager>= 8.0.0, <= 8.2.4.0
OracleCommunications Unified Inventory Management7.4.1
OracleDocumaker>= 12.6.0, <= 12.6.4
OracleEnterprise Data Quality12.2.1.3.0
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.8, <= 8.1.1
OracleHealthcare Data Repository8.1.0
OracleInsurance Policy Administration>= 11.0, <= 11.3.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-22118?

CVE-2021-22118 is a vulnerability with a CVSS score of 7.8 (HIGH). In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a...

How severe is CVE-2021-22118?

CVE-2021-22118 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-22118?

Check the references section above for vendor advisories and patch information. Affected products include: Vmware Spring Framework, Oracle Commerce Guided Search, Oracle Communications Brm - Elastic Charging Engine, Oracle Communications Cloud Native Core Binding Support Function, Oracle Communications Cloud Native Core Policy.