CVE-2010-1622
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 51.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 51.85% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- oracle/fusion middleware · springsource/spring framework
- Source
- secalert@redhat.com
References
- http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.htmlVendor Advisory
- http://geronimo.apache.org/21x-security-report.htmlVendor Advisory
- http://geronimo.apache.org/22x-security-report.htmlVendor Advisory
- http://secunia.com/advisories/41016
- http://secunia.com/advisories/41025
- http://secunia.com/advisories/43087
- http://www.exploit-db.com/exploits/13918Exploit
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- http://www.redhat.com/support/errata/RHSA-2011-0175.html
- http://www.securityfocus.com/archive/1/511877Exploit
- http://www.securityfocus.com/bid/40954
- http://www.securitytracker.com/id/1033898
- http://www.springsource.com/security/cve-2010-1622Exploit, Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0237
- http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.htmlVendor Advisory
- http://geronimo.apache.org/21x-security-report.htmlVendor Advisory
- http://geronimo.apache.org/22x-security-report.htmlVendor Advisory
- http://secunia.com/advisories/41016
- http://secunia.com/advisories/41025
- http://secunia.com/advisories/43087
- http://www.exploit-db.com/exploits/13918Exploit
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- http://www.redhat.com/support/errata/RHSA-2011-0175.html
- http://www.securityfocus.com/archive/1/511877Exploit
- http://www.securityfocus.com/bid/40954
- http://www.securitytracker.com/id/1033898
- http://www.springsource.com/security/cve-2010-1622Exploit, Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0237
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.