SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-5398

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response…

HIGH 7.5EPSS 88.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 88.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
88.40% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-79, CWE-494
Affected
vmware/spring framework · oracle/application testing suite · oracle/communications billing and revenue management elastic charging engine · oracle/communications cloud native core policy · oracle/communications diameter signaling router · oracle/communications element manager · oracle/communications policy management · oracle/communications session report manager · oracle/communications session route manager · oracle/enterprise manager base platform · oracle/financial services regulatory reporting with agilereporter · oracle/flexcube private banking · oracle/healthcare master person index · oracle/insurance calculation engine · oracle/insurance policy administration j2ee · oracle/insurance rules palette · oracle/mysql · oracle/rapid planning · oracle/retail assortment planning · oracle/retail back office · +13 more
Source
security@pivotal.io

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.