Description
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- NETAPP / OnCommand Insight
- NETAPP / OnCommand Unified Manager9.4 –
- NETAPP / OnCommand Unified Manager7.3 –
- NETAPP / OnCommand Workflow Automation
- NETAPP / SnapCenter
- NETAPP / storage_automation_store
- oracle / agile_product_lifecycle_management9.3.6 – 9.3.6
- oracle / agile_product_lifecycle_management9.3.5 – 9.3.5
- oracle / agile_product_lifecycle_management9.3.3 – 9.3.3
- oracle / agile_product_lifecycle_management9.3.4 – 9.3.4
- oracle / Application Testing Suite13.2.0.1 – 13.2.0.1
- oracle / Application Testing Suite13.3.0.1 – 13.3.0.1
- oracle / Application Testing Suite10.1 – 10.1
- oracle / Application Testing Suite12.5.0.3 – 12.5.0.3
- oracle / Application Testing Suite13.1.0.1 – 13.1.0.1
- oracle / big_data_discovery1.6.0 – 1.6.0
- oracle / communications_converged_application_server7.0.0.1
- oracle / communications_diameter_signaling_router8.3
- oracle / communications_network_integrity7.3.2 – 7.3.6
- oracle / communications_performance_intelligence_center10.2.1
- oracle / communications_services_gatekeeper6.1.0.4.0
- oracle / endeca_information_discovery_integrator3.2.0 – 3.2.0
- oracle / endeca_information_discovery_integrator3.1.0 – 3.1.0
- oracle / enterprise_manager_for_mysql_database13.2 – 13.2
- oracle / enterprise_manager_ops_center12.2.2 – 12.2.2
- oracle / enterprise_manager_ops_center12.3.3 – 12.3.3
- oracle / enterprise_repository11.1.1.7.0 – 11.1.1.7.0
- oracle / enterprise_repository12.1.3.0.0 – 12.1.3.0.0
- oracle / goldengate_for_big_data12.3.1.1 – 12.3.1.1
- oracle / goldengate_for_big_data12.3.2.1 – 12.3.2.1
- oracle / goldengate_for_big_data12.2.0.1 – 12.2.0.1
- oracle / healthcare_master_person_index3.0 – 3.0
- oracle / healthcare_master_person_index4.0 – 4.0
- oracle / health_sciences_information_manager3.0 – 3.0
- oracle / hospitality_guest_access4.2.0 – 4.2.0
- oracle / hospitality_guest_access4.2.1 – 4.2.1
- oracle / insurance_calculation_engine10.2.1 – 10.2.1
- oracle / insurance_calculation_engine10.2 – 10.2
- oracle / insurance_calculation_engine10.1.1 – 10.1.1
- oracle / insurance_policy_administration10.0 – 10.0
- oracle / insurance_policy_administration11.0 – 11.0
- oracle / insurance_policy_administration10.1 – 10.1
- oracle / insurance_policy_administration10.2 – 10.2
- oracle / insurance_rules_palette10.1 – 10.1
- oracle / insurance_rules_palette10.0 – 10.0
- oracle / insurance_rules_palette10.2 – 10.2
- oracle / insurance_rules_palette11.0 – 11.0
- oracle / insurance_rules_palette11.1 – 11.1
- oracle / micros_lucas2.9.5 – 2.9.5
- oracle / MySQL Enterprise Monitor8.0.2.8191
- oracle / peoplesoft_enterprise_fin_install9.2 – 9.2
- oracle / retail_assortment_planning16.0 – 16.0
- oracle / retail_assortment_planning14.1 – 14.1
- oracle / retail_assortment_planning15.0 – 15.0
- oracle / retail_back_office14.0 – 14.0
- oracle / retail_back_office14.1 – 14.1
- oracle / retail_central_office14.1 – 14.1
- oracle / retail_central_office14.0 – 14.0
- oracle / retail_customer_insights15.0 – 15.0
- oracle / retail_customer_insights16.0 – 16.0
- oracle / retail_financial_integration15.0 – 15.0
- oracle / retail_financial_integration16.0 – 16.0
- oracle / retail_financial_integration14.0 – 14.0
- oracle / retail_financial_integration14.1 – 14.1
- oracle / retail_financial_integration13.2 – 13.2
- oracle / retail_integration_bus14.1.2 – 14.1.2
- oracle / retail_point-of-service14.0 – 14.0
- oracle / retail_point-of-service14.1 – 14.1
- oracle / retail_returns_management14.0 – 14.0
- oracle / retail_returns_management14.1 – 14.1
- oracle / retail_xstore_point_of_service17.0 – 17.0
- oracle / service_architecture_leveraging_tuxedo12.2.2.0.0 – 12.2.2.0.0
- oracle / service_architecture_leveraging_tuxedo12.1.3.0.0 – 12.1.3.0.0
- oracle / tape_library_acsls8.4 – 8.4
- oracle / weblogic_server12.2.1.3 – 12.2.1.3
- oracle / weblogic_server12.2.1.2 – 12.2.1.2
- oracle / weblogic_server12.1.3.0 – 12.1.3.0
- oracle / weblogic_server10.3.6.0 – 10.3.6.0
- Pivotal / Spring Framework5.0.5 – 5.0.5
- pivotal_software / spring_security
- RedHat / fuse7.3.0 – 7.3.0
- VMware / Spring Framework5.0.5 – 5.0.5
References
- MISChttp://www.securityfocus.com/bid/104222
- MISChttp://www.securitytracker.com/id/1041888
- MISChttp://www.securitytracker.com/id/1041896
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2019:2413
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpuapr2020.html
- VENDOR_ADVISORYhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- VENDOR_ADVISORYhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpujul2020.html
- VENDOR_ADVISORYhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- VENDOR_ADVISORYhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- VENDOR_ADVISORYhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpujan2020.html
- MISChttps://security.netapp.com/advisory/ntap-20181018-0002/
- MISChttps://pivotal.io/security/cve-2018-1258
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpujan2021.html
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpuoct2021.html
Updated 17m ago · 8 sources