VulnerabilityModified
CVE-2016-9878
Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
HIGH 7.5EPSS 5.75%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 5.75% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- pivotal software/spring framework · vmware/spring framework
- Source
- security_alert@emc.com
References
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.securityfocus.com/bid/95072Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040698
- https://access.redhat.com/errata/RHSA-2017:3115
- https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html
- https://pivotal.io/security/cve-2016-9878Vendor Advisory
- https://security.netapp.com/advisory/ntap-20180419-0002/
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.securityfocus.com/bid/95072Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040698
- https://access.redhat.com/errata/RHSA-2017:3115
- https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html
- https://pivotal.io/security/cve-2016-9878Vendor Advisory
- https://security.netapp.com/advisory/ntap-20180419-0002/
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.