CVE-2020-5421
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
Published:Sep 17, 2020
Last Modified:Nov 21, 2024
EPS:Sep 19, 2020
EPSS Score:0.59873
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Netapp
Product
Oncommand Insight
Netapp
Oncommand Insight
Vendor
Netapp
Product
Snap Creator Framework
Netapp
Snap Creator Framework
Vendor
Netapp
Product
Snapcenter
Netapp
Snapcenter
Vendor
Oracle
Product
Commerce Guided Search
Oracle
Commerce Guided Search
Vendor
Oracle
Product
Communications Brm
Oracle
Communications Brm
Vendor
Oracle
Product
Communications Design Studio
Oracle
Communications Design Studio
Vendor
Oracle
Product
Communications Session Report Manager
Oracle
Communications Session Report Manager
Vendor
Oracle
Product
Communications Unified Inventory Management
Oracle
Communications Unified Inventory Management
Vendor
Oracle
Product
Endeca Information Discovery Integrator
Oracle
Endeca Information Discovery Integrator
Vendor
Oracle
Product
Enterprise Data Quality
Oracle
Enterprise Data Quality
Vendor
Oracle
Product
Financial Services Analytical Applications Infrastructure
Oracle
Financial Services Analytical Applications Infrastructure
Vendor
Oracle
Product
Flexcube Private Banking
Oracle
Flexcube Private Banking
Vendor
Oracle
Product
Fusion Middleware
Oracle
Fusion Middleware
Vendor
Oracle
Product
Goldengate Application Adapters
Oracle
Goldengate Application Adapters
Vendor
Oracle
Product
Healthcare Master Person Index
Oracle
Healthcare Master Person Index
Vendor
Oracle
Product
Hyperion Infrastructure Technology
Oracle
Hyperion Infrastructure Technology
Vendor
Oracle
Product
Insurance Policy Administration
Oracle
Insurance Policy Administration
Vendor
Oracle
Product
Insurance Rules Palette
Oracle
Insurance Rules Palette
Vendor
Oracle
Product
Mysql Enterprise Monitor
Oracle
Mysql Enterprise Monitor
Vendor
Oracle
Product
Primavera Gateway
Oracle
Primavera Gateway
Vendor
Oracle
Product
Primavera P6 Enterprise Project Portfolio Management
Oracle
Primavera P6 Enterprise Project Portfolio Management
Vendor
Oracle
Product
Retail Assortment Planning
Oracle
Retail Assortment Planning
Vendor
Oracle
Product
Retail Bulk Data Integration
Oracle
Retail Bulk Data Integration
Vendor
Oracle
Product
Retail Customer Engagement
Oracle
Retail Customer Engagement
Vendor
Oracle
Product
Retail Customer Management And Segmentation Foundation
Oracle
Retail Customer Management And Segmentation Foundation
Vendor
Oracle
Product
Retail Financial Integration
Oracle
Retail Financial Integration
Vendor
Oracle
Product
Retail Integration Bus
Oracle
Retail Integration Bus
Vendor
Oracle
Product
Retail Invoice Matching
Oracle
Retail Invoice Matching
Vendor
Oracle
Product
Retail Merchandising System
Oracle
Retail Merchandising System
Vendor
Oracle
Product
Retail Order Broker
Oracle
Retail Order Broker
Vendor
Oracle
Product
Retail Predictive Application Server
Oracle
Retail Predictive Application Server
Vendor
Oracle
Product
Retail Returns Management
Oracle
Retail Returns Management
Vendor
Oracle
Product
Retail Service Backbone
Oracle
Retail Service Backbone
Vendor
Oracle
Product
Retail Xstore Point Of Service
Oracle
Retail Xstore Point Of Service
Vendor
Oracle
Product
Storagetek Acsls
Oracle
Storagetek Acsls
Vendor
Oracle
Product
Storagetek Tape Analytics Sw Tool
Oracle
Storagetek Tape Analytics Sw Tool
Vendor
Oracle
Product
Weblogic Server
Oracle
Weblogic Server
Vendor
Redhat
Product
Jboss Fuse
Redhat
Jboss Fuse
Vendor
Vmware
Product
Spring Framework
Vmware
Spring Framework
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
