← All CVEs

CVE-2020-5398

high · 7.5

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

7.5
CVSS
88.4%
EPSS (exploit prob.)
100th
EPSS percentile
2020-01-17
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-79CWE-494

Affected products

VendorProductAffected versions
vmwarespring_framework>= 5.0.0, < 5.0.16
vmwarespring_framework>= 5.1.0, < 5.1.13
vmwarespring_framework>= 5.2.0, < 5.2.3
oracleapplication_testing_suite13.3.0.1
oraclecommunications_billing_and_revenue_management_elastic_charging_engine11.3
oraclecommunications_billing_and_revenue_management_elastic_charging_engine12.0
oraclecommunications_cloud_native_core_policy1.5.0
oraclecommunications_diameter_signaling_router>= 8.0.0, <= 8.2.2
oraclecommunications_element_manager8.1.1
oraclecommunications_element_manager8.2.0
oraclecommunications_element_manager8.2.1
oraclecommunications_policy_management12.5.0
oraclecommunications_session_report_manager8.1.1
oraclecommunications_session_report_manager8.2.0
oraclecommunications_session_report_manager8.2.1
oraclecommunications_session_route_manager8.1.1
oraclecommunications_session_route_manager8.2.0
oraclecommunications_session_route_manager8.2.1
oracleenterprise_manager_base_platform13.2.1.0
oraclefinancial_services_regulatory_reporting_with_agilereporter8.0.9.2.0
oracleflexcube_private_banking12.0.0
oracleflexcube_private_banking12.1.0
oraclehealthcare_master_person_index4.0.2
oracleinsurance_calculation_engine>= 11.0.0, <= 11.3.1
oracleinsurance_policy_administration_j2ee10.2.0
oracleinsurance_policy_administration_j2ee10.2.4
oracleinsurance_policy_administration_j2ee11.0.2
oracleinsurance_policy_administration_j2ee11.1.0
oracleinsurance_policy_administration_j2ee11.2.0
oracleinsurance_policy_administration_j2ee11.2.2.0
oracleinsurance_rules_palette10.2.0
oracleinsurance_rules_palette10.2.4
oracleinsurance_rules_palette11.0.2
oracleinsurance_rules_palette11.1.0
oracleinsurance_rules_palette11.2.0
oraclemysql>= 4.0.0, <= 4.0.12
oraclemysql>= 8.0.0, <= 8.0.20
oraclerapid_planning12.1
oraclerapid_planning12.2
oracleretail_assortment_planning15.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-5398