cbcvebase.
CVE-2021-22118
published 2021-05-27

CVE-2021-22118: In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

Affected

49 ranges· showing 25
VendorProductVersion rangeFixed in
debianlibspring-java
oraclecommerce_guided_search
oraclecommunications_brm_elastic_charging_engine
oraclecommunications_cloud_native_core_binding_support_function
oraclecommunications_cloud_native_core_policy
oraclecommunications_cloud_native_core_security_edge_protection_proxy
oraclecommunications_cloud_native_core_service_communication_proxy
oraclecommunications_cloud_native_core_unified_data_repository
oraclecommunications_diameter_intelligence_hub8.0.0 – 8.1.0
oraclecommunications_diameter_intelligence_hub8.2.0 – 8.2.3
oraclecommunications_element_manager8.2.0 – 8.2.4.0
oraclecommunications_interactive_session_recorder
oraclecommunications_network_integrity
oraclecommunications_session_report_manager8.0.0 – 8.2.4.0
oraclecommunications_session_route_manager8.0.0 – 8.2.4.0
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oracledocumaker12.6.0 – 12.6.4
oracleenterprise_data_quality
oracleenterprise_data_quality
oraclefinancial_services_analytical_applications_infrastructure8.0.8 – 8.1.1
oraclehealthcare_data_repository
oracleinsurance_policy_administration11.0 – 11.3.1
oracleinsurance_rules_palette

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH