In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Netapp
Subscribe
|
|
|
Oracle
Subscribe
|
Commerce Guided Search
Subscribe
Communications Brm
Subscribe
Communications Design Studio
Subscribe
Communications Session Report Manager
Subscribe
Communications Unified Inventory Management
Subscribe
Endeca Information Discovery Integrator
Subscribe
Enterprise Data Quality
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Flexcube Private Banking
Subscribe
Fusion Middleware
Subscribe
Goldengate Application Adapters
Subscribe
Healthcare Master Person Index
Subscribe
Hyperion Infrastructure Technology
Subscribe
Insurance Policy Administration
Subscribe
Insurance Rules Palette
Subscribe
Mysql Enterprise Monitor
Subscribe
Primavera Gateway
Subscribe
Primavera P6 Enterprise Project Portfolio Management
Subscribe
Retail Assortment Planning
Subscribe
Retail Bulk Data Integration
Subscribe
Retail Customer Engagement
Subscribe
Retail Customer Management And Segmentation Foundation
Subscribe
Retail Financial Integration
Subscribe
Retail Integration Bus
Subscribe
Retail Invoice Matching
Subscribe
Retail Merchandising System
Subscribe
Retail Order Broker
Subscribe
Retail Predictive Application Server
Subscribe
Retail Returns Management
Subscribe
Retail Service Backbone
Subscribe
Retail Xstore Point Of Service
Subscribe
Storagetek Acsls
Subscribe
Storagetek Tape Analytics Sw Tool
Subscribe
Weblogic Server
Subscribe
|
|
Redhat
Subscribe
|
Jboss Fuse
Subscribe
|
|
Vmware
Subscribe
|
Spring Framework
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rv39-3qh7-9v7w | Improper Input Validation in Spring Framework |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: pivotal
Published:
Updated: 2024-09-17T03:58:43.873Z
Reserved: 2020-01-03T00:00:00
Link: CVE-2020-5421
No data.
Status : Modified
Published: 2020-09-19T04:15:11.527
Modified: 2024-11-21T05:34:08.303
Link: CVE-2020-5421
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA