cbcvebase.
CVE-2020-5398
published 2020-01-17

CVE-2020-5398: In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a…

high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

Affected

65 ranges· showing 25
VendorProductVersion rangeFixed in
debianlibspring-java
oracleapplication_testing_suite
oraclecommunications_billing_and_revenue_management_elastic_charging_engine
oraclecommunications_billing_and_revenue_management_elastic_charging_engine
oraclecommunications_cloud_native_core_policy
oraclecommunications_diameter_signaling_router8.0.0 – 8.2.2
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_policy_management
oraclecommunications_session_report_manager
oraclecommunications_session_report_manager
oraclecommunications_session_report_manager
oraclecommunications_session_route_manager
oraclecommunications_session_route_manager
oraclecommunications_session_route_manager
oracleenterprise_manager_base_platform
oraclefinancial_services_regulatory_reporting_with_agilereporter
oracleflexcube_private_banking
oracleflexcube_private_banking
oraclehealthcare_master_person_index
oracleinsurance_calculation_engine11.0.0 – 11.3.1
oracleinsurance_policy_administration_j2ee
oracleinsurance_policy_administration_j2ee
oracleinsurance_policy_administration_j2ee

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.5HIGH