cbcvebase.
CVE-2020-5421
published 2020-09-19

CVE-2020-5421: In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks…

PriorityP341medium6.5CVSS 3.1
AVNACHPRLUIRSCCLIHAN
EPSS
10.74%
95.3th percentile
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.

Affected

75 ranges· showing 25
VendorProductVersion rangeFixed in
debianlibspring-java< libspring-java 4.3.30-1 (bookworm)libspring-java 4.3.30-1 (bookworm)
oraclecommerce_guided_search
oraclecommunications_brm
oraclecommunications_brm
oraclecommunications_design_studio
oraclecommunications_design_studio
oraclecommunications_design_studio
oraclecommunications_session_report_manager8.2.1 – 8.2.2.1
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oracleendeca_information_discovery_integrator
oracleenterprise_data_quality
oracleenterprise_data_quality
oraclefinancial_services_analytical_applications_infrastructure8.0.6 – 8.1.0
oracleflexcube_private_banking
oracleflexcube_private_banking
oraclefusion_middleware
oraclefusion_middleware
oraclegoldengate_application_adapters
oraclehealthcare_master_person_index
oraclehyperion_infrastructure_technology
oracleinsurance_policy_administration
oracleinsurance_policy_administration
oracleinsurance_policy_administration
oracleinsurance_policy_administration11.1.0 – 11.3.0

Detection & IOCsextracted from sources · hover to see the quote

  • RFD attack bypass vector: look for HTTP requests containing a jsessionid path parameter appended to URLs (e.g., ';jsessionid=...' in the URL path), which may be used to bypass Content-Disposition protections in Spring Framework
  • Focus detection on Spring Framework versions 5.2.0–5.2.8, 5.1.0–5.1.17, 5.0.0–5.0.18, and 4.3.0–4.3.28 as the affected range for this RFD bypass
  • The attack surface is the spring-web component specifically; systems not shipping spring-web are not affected and can be excluded from detection scope
  • ·Exploitability is browser-dependent; not all browsers will be susceptible to the RFD bypass via the jsessionid path parameter
  • ·Oracle rates this as non-remotely-exploitable (Remote exploit: No) in its risk matrices, which may affect prioritization in network-exposed deployments

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N
nvdv3.08.7HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
nvdv2.03.6LOWAV:N/AC:H/Au:S/C:P/I:P/A:N
ghsa9.6CRITICAL
osv9.6CRITICAL
vendor_debian9.6LOW
vendor_redhat9.6CRITICAL
vendor_oracle8.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.