SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-5421

In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a…

MEDIUM 6.5EPSS 10.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 10.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N
EPSS
10.74% probability · 96th percentile
CISA KEV
Not listed
Affected
vmware/spring framework · oracle/commerce guided search · oracle/communications brm · oracle/communications design studio · oracle/communications session report manager · oracle/communications unified inventory management · oracle/endeca information discovery integrator · oracle/enterprise data quality · oracle/financial services analytical applications infrastructure · oracle/flexcube private banking · oracle/fusion middleware · oracle/goldengate application adapters · oracle/healthcare master person index · oracle/hyperion infrastructure technology · oracle/insurance policy administration · oracle/insurance rules palette · oracle/mysql enterprise monitor · oracle/primavera gateway · oracle/primavera p6 enterprise project portfolio management · oracle/retail assortment planning · +18 more
Source
security@pivotal.io

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.