CVE-2021-22118
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
Published:May 25, 2021
Last Modified:Nov 21, 2024
EPS:May 27, 2021
EPSS Score:0.00253
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Netapp
Product
Hci
Netapp
Hci
Vendor
Netapp
Product
Management Services For Element Software
Netapp
Management Services For Element Software
Vendor
Oracle
Product
Commerce Guided Search
Oracle
Commerce Guided Search
Vendor
Oracle
Product
Communications Brm - Elastic Charging Engine
Oracle
Communications Brm - Elastic Charging Engine
Vendor
Oracle
Product
Communications Cloud Native Core Binding Support Function
Oracle
Communications Cloud Native Core Binding Support Function
Vendor
Oracle
Product
Communications Cloud Native Core Policy
Oracle
Communications Cloud Native Core Policy
Vendor
Oracle
Product
Communications Cloud Native Core Security Edge Protection Proxy
Oracle
Communications Cloud Native Core Security Edge Protection Proxy
Vendor
Oracle
Product
Communications Cloud Native Core Service Communication Proxy
Oracle
Communications Cloud Native Core Service Communication Proxy
Vendor
Oracle
Product
Communications Cloud Native Core Unified Data Repository
Oracle
Communications Cloud Native Core Unified Data Repository
Vendor
Oracle
Product
Communications Diameter Intelligence Hub
Oracle
Communications Diameter Intelligence Hub
Vendor
Oracle
Product
Communications Element Manager
Oracle
Communications Element Manager
Vendor
Oracle
Product
Communications Interactive Session Recorder
Oracle
Communications Interactive Session Recorder
Vendor
Oracle
Product
Communications Network Integrity
Oracle
Communications Network Integrity
Vendor
Oracle
Product
Communications Session Report Manager
Oracle
Communications Session Report Manager
Vendor
Oracle
Product
Communications Session Route Manager
Oracle
Communications Session Route Manager
Vendor
Oracle
Product
Communications Unified Inventory Management
Oracle
Communications Unified Inventory Management
Vendor
Oracle
Product
Documaker
Oracle
Documaker
Vendor
Oracle
Product
Enterprise Data Quality
Oracle
Enterprise Data Quality
Vendor
Oracle
Product
Financial Services Analytical Applications Infrastructure
Oracle
Financial Services Analytical Applications Infrastructure
Vendor
Oracle
Product
Healthcare Data Repository
Oracle
Healthcare Data Repository
Vendor
Oracle
Product
Insurance Policy Administration
Oracle
Insurance Policy Administration
Vendor
Oracle
Product
Insurance Rules Palette
Oracle
Insurance Rules Palette
Vendor
Oracle
Product
Mysql Enterprise Monitor
Oracle
Mysql Enterprise Monitor
Vendor
Oracle
Product
Retail Assortment Planning
Oracle
Retail Assortment Planning
Vendor
Oracle
Product
Retail Customer Management And Segmentation Foundation
Oracle
Retail Customer Management And Segmentation Foundation
Vendor
Oracle
Product
Retail Financial Integration
Oracle
Retail Financial Integration
Vendor
Oracle
Product
Retail Integration Bus
Oracle
Retail Integration Bus
Vendor
Oracle
Product
Retail Merchandising System
Oracle
Retail Merchandising System
Vendor
Oracle
Product
Retail Order Broker
Oracle
Retail Order Broker
Vendor
Oracle
Product
Retail Predictive Application Server
Oracle
Retail Predictive Application Server
Vendor
Oracle
Product
Utilities Testing Accelerator
Oracle
Utilities Testing Accelerator
Vendor
Redhat
Product
Integration
Redhat
Integration
Vendor
Redhat
Product
Jboss Fuse
Redhat
Jboss Fuse
Vendor
Vmware
Product
Spring Framework
Vmware
Spring Framework
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
