CVE Feed

    Dashboard / CVE / CVE-2020-5421

    CVE-2020-5421

    In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.

    Published:Sep 17, 2020
    Last Modified:Nov 21, 2024
    EPS:Sep 19, 2020
    EPSS Score:0.59873
    CVSS Score:6.5

    Affected Products

    Vendor
    Netapp
    Product
    Oncommand Insight
    Vendor
    Netapp
    Product
    Snap Creator Framework
    Vendor
    Netapp
    Product
    Snapcenter
    Vendor
    Oracle
    Product
    Commerce Guided Search
    Vendor
    Oracle
    Product
    Communications Brm
    Vendor
    Oracle
    Product
    Communications Design Studio
    Vendor
    Oracle
    Product
    Communications Session Report Manager
    Vendor
    Oracle
    Product
    Communications Unified Inventory Management
    Vendor
    Oracle
    Product
    Endeca Information Discovery Integrator
    Vendor
    Oracle
    Product
    Enterprise Data Quality
    Vendor
    Oracle
    Product
    Financial Services Analytical Applications Infrastructure
    Vendor
    Oracle
    Product
    Flexcube Private Banking
    Vendor
    Oracle
    Product
    Fusion Middleware
    Vendor
    Oracle
    Product
    Goldengate Application Adapters
    Vendor
    Oracle
    Product
    Healthcare Master Person Index
    Vendor
    Oracle
    Product
    Hyperion Infrastructure Technology
    Vendor
    Oracle
    Product
    Insurance Policy Administration
    Vendor
    Oracle
    Product
    Insurance Rules Palette
    Vendor
    Oracle
    Product
    Mysql Enterprise Monitor
    Vendor
    Oracle
    Product
    Primavera Gateway
    Vendor
    Oracle
    Product
    Primavera P6 Enterprise Project Portfolio Management
    Vendor
    Oracle
    Product
    Retail Assortment Planning
    Vendor
    Oracle
    Product
    Retail Bulk Data Integration
    Vendor
    Oracle
    Product
    Retail Customer Engagement
    Vendor
    Oracle
    Product
    Retail Customer Management And Segmentation Foundation
    Vendor
    Oracle
    Product
    Retail Financial Integration
    Vendor
    Oracle
    Product
    Retail Integration Bus
    Vendor
    Oracle
    Product
    Retail Invoice Matching
    Vendor
    Oracle
    Product
    Retail Merchandising System
    Vendor
    Oracle
    Product
    Retail Order Broker
    Vendor
    Oracle
    Product
    Retail Predictive Application Server
    Vendor
    Oracle
    Product
    Retail Returns Management
    Vendor
    Oracle
    Product
    Retail Service Backbone
    Vendor
    Oracle
    Product
    Retail Xstore Point Of Service
    Vendor
    Oracle
    Product
    Storagetek Acsls
    Vendor
    Oracle
    Product
    Storagetek Tape Analytics Sw Tool
    Vendor
    Oracle
    Product
    Weblogic Server
    Vendor
    Redhat
    Product
    Jboss Fuse
    Vendor
    Vmware
    Product
    Spring Framework

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High