CVE-2010-3700
published 2010-10-29CVE-2010-3700: VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.67%
74.2th percentile
VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| acegisecurity | acegi-security | — | — |
| acegisecurity | acegi-security | — | — |
| acegisecurity | acegi-security | — | — |
| acegisecurity | acegi-security | — | — |
| acegisecurity | acegi-security | — | — |
| acegisecurity | acegi-security | — | — |
| acegisecurity | acegi-security | — | — |
| acegisecurity | acegi-security | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Authentication Bypass Using an Alternate Path or Channel in SpringSource Spring Security and Acegi Security
osv·2022-05-14
CVE-2010-3700 [MEDIUM] Authentication Bypass Using an Alternate Path or Channel in SpringSource Spring Security and Acegi Security
Authentication Bypass Using an Alternate Path or Channel in SpringSource Spring Security and Acegi Security
VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.
GHSA
Authentication Bypass Using an Alternate Path or Channel in SpringSource Spring Security and Acegi Security
ghsa·2022-05-14
CVE-2010-3700 [MEDIUM] CWE-288 Authentication Bypass Using an Alternate Path or Channel in SpringSource Spring Security and Acegi Security
Authentication Bypass Using an Alternate Path or Channel in SpringSource Spring Security and Acegi Security
VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/68931http://secunia.com/advisories/42024http://www.securityfocus.com/archive/1/514517/100/0/threadedhttp://www.securityfocus.com/bid/44496http://www.springsource.com/security/cve-2010-3700https://issues.apache.org/bugzilla/show_bug.cgi?id=25015http://osvdb.org/68931http://secunia.com/advisories/42024http://www.securityfocus.com/archive/1/514517/100/0/threadedhttp://www.securityfocus.com/bid/44496http://www.springsource.com/security/cve-2010-3700https://issues.apache.org/bugzilla/show_bug.cgi?id=25015
2010-10-29
Published