CVE-2020-5398
high · 7.5In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
7.5
CVSS
88.4%
EPSS (exploit prob.)
100th
EPSS percentile
2020-01-17
Published
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-79CWE-494
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| vmware | spring_framework | >= 5.0.0, < 5.0.16 |
| vmware | spring_framework | >= 5.1.0, < 5.1.13 |
| vmware | spring_framework | >= 5.2.0, < 5.2.3 |
| oracle | application_testing_suite | 13.3.0.1 |
| oracle | communications_billing_and_revenue_management_elastic_charging_engine | 11.3 |
| oracle | communications_billing_and_revenue_management_elastic_charging_engine | 12.0 |
| oracle | communications_cloud_native_core_policy | 1.5.0 |
| oracle | communications_diameter_signaling_router | >= 8.0.0, <= 8.2.2 |
| oracle | communications_element_manager | 8.1.1 |
| oracle | communications_element_manager | 8.2.0 |
| oracle | communications_element_manager | 8.2.1 |
| oracle | communications_policy_management | 12.5.0 |
| oracle | communications_session_report_manager | 8.1.1 |
| oracle | communications_session_report_manager | 8.2.0 |
| oracle | communications_session_report_manager | 8.2.1 |
| oracle | communications_session_route_manager | 8.1.1 |
| oracle | communications_session_route_manager | 8.2.0 |
| oracle | communications_session_route_manager | 8.2.1 |
| oracle | enterprise_manager_base_platform | 13.2.1.0 |
| oracle | financial_services_regulatory_reporting_with_agilereporter | 8.0.9.2.0 |
| oracle | flexcube_private_banking | 12.0.0 |
| oracle | flexcube_private_banking | 12.1.0 |
| oracle | healthcare_master_person_index | 4.0.2 |
| oracle | insurance_calculation_engine | >= 11.0.0, <= 11.3.1 |
| oracle | insurance_policy_administration_j2ee | 10.2.0 |
| oracle | insurance_policy_administration_j2ee | 10.2.4 |
| oracle | insurance_policy_administration_j2ee | 11.0.2 |
| oracle | insurance_policy_administration_j2ee | 11.1.0 |
| oracle | insurance_policy_administration_j2ee | 11.2.0 |
| oracle | insurance_policy_administration_j2ee | 11.2.2.0 |
| oracle | insurance_rules_palette | 10.2.0 |
| oracle | insurance_rules_palette | 10.2.4 |
| oracle | insurance_rules_palette | 11.0.2 |
| oracle | insurance_rules_palette | 11.1.0 |
| oracle | insurance_rules_palette | 11.2.0 |
| oracle | mysql | >= 4.0.0, <= 4.0.12 |
| oracle | mysql | >= 8.0.0, <= 8.0.20 |
| oracle | rapid_planning | 12.1 |
| oracle | rapid_planning | 12.2 |
| oracle | retail_assortment_planning | 15.0 |
Check a specific version with /api/v1/cve/match.
References
- https://lists.apache.org/thread.html/r028977b9b9d44a89823639aa3296fb0f0cfdd76b4450df89d3c4fbbf%40%3Cissues.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r0f2d0ae1bad2edb3d4a863d77f3097b5e88cfbdae7b809f4f42d6aad%40%3Cissues.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r0f3530f7cb510036e497532ffc4e0bd0b882940448cf4e233994b08b%40%3Ccommits.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r1accbd4f31ad2f40e1661d70a4510a584eb3efd1e32e8660ccf46676%40%3Ccommits.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r1bc5d673c01cfbb8e4a91914e9748ead3e5f56b61bca54d314c0419b%40%3Cissues.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r1c679c43fa4f7846d748a937955c7921436d1b315445978254442163%40%3Ccommits.ambari.apache.org%3E
- https://lists.apache.org/thread.html/r1eccdbd7986618a7319ee7a533bd9d9bf6e8678e59dd4cca9b5b2d7a%40%3Cissues.ambari.apache.org%3E
- https://lists.apache.org/thread.html/r27552d2fa10d96f2810c50d16ad1fd1899e37796c81a0c5e7585a02d%40%3Cdev.rocketmq.apache.org%3E
- https://lists.apache.org/thread.html/r2dfd5b331b46d3f90c4dd63a060e9f04300468293874bd7e41af7163%40%3Cissues.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r3765353ff434fd00d8fa5a44734b3625a06eeb2a3fb468da7dfae134%40%3Ccommits.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r4639e821ef9ca6ca10887988f410a60261400a7766560e7a97a22efc%40%3Ccommits.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r4b1886e82cc98ef38f582fef7d4ea722e3fcf46637cd4674926ba682%40%3Cissues.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r5c95eff679dfc642e9e4ab5ac6d202248a59cb1e9457cfbe8b729ac5%40%3Cissues.ambari.apache.org%3E
- https://lists.apache.org/thread.html/r645408661a8df9158f49e337072df39838fa76da629a7e25a20928a6%40%3Cdev.rocketmq.apache.org%3E
- https://lists.apache.org/thread.html/r6dac0e365d1b2df9a7ffca12b4195181ec14ff0abdf59e1fdb088ce5%40%3Ccommits.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r712a6fce928e24e7b6ec30994a7e115a70f1f6e4cf2c2fbf0347ce46%40%3Ccommits.servicecomb.apache.org%3E
- https://lists.apache.org/thread.html/r7361bfe84bde9d233f9800c3a96673e7bd81207549ced0236f07a29d%40%3Cissues.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r74f81f93a9b69140fe41e236afa7cbe8dfa75692e7ab31a468fddaa0%40%3Ccommits.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r7d5e518088e2e778928b02bcd3be3b948b59acefe2f0ebb57ec2ebb0%40%3Ccommits.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r8736185eb921022225a83e56d7285a217fd83f5524bd64a6ca3bf5cc%40%3Cissues.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r881fb5a95ab251106fed38f836257276feb026bfe01290e72ff91c2a%40%3Ccommits.servicecomb.apache.org%3E
- https://lists.apache.org/thread.html/r8b496b1743d128e6861ee0ed3c3c48cc56c505b38f84fa5baf7ae33a%40%3Cdev.ambari.apache.org%3E
- https://lists.apache.org/thread.html/r8cc37a60a5056351377ee5f1258f2a4fdd39822a257838ba6bcc1e88%40%3Ccommits.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r9f13cccb214495e14648d2c9b8f2c6072fd5219e74502dd35ede81e1%40%3Cdev.ambari.apache.org%3E
- https://lists.apache.org/thread.html/r9fb1ee08cf337d16c3364feb0f35a072438c1a956afd7b77859aa090%40%3Cissues.karaf.apache.org%3E
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-5398