5.3

CVE-2020-5397

Exploit

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

Data is provided by the National Vulnerability Database (NVD)
VMwareSpring Framework Version >= 5.2.0 < 5.2.3
OracleApplication Testing Suite Version13.3.0.1
OracleCommunications Diameter Signaling Router Version >= 8.0.0 <= 8.2.2
OracleFlexcube Private Banking Version12.0.0
OracleFlexcube Private Banking Version12.1.0
OracleInsurance Calculation Engine Version >= 11.0.0 <= 11.3.1
OracleInsurance Rules Palette Version10.2.0
OracleInsurance Rules Palette Version10.2.4
OracleInsurance Rules Palette Version11.0.2
OracleInsurance Rules Palette Version11.1.0
OracleInsurance Rules Palette Version11.2.0
OracleMysql Enterprise Monitor Version >= 4.0.0 <= 4.0.12
OracleMysql Enterprise Monitor Version >= 8.0.0 <= 8.0.20
OracleRapid Planning Version12.1
OracleRapid Planning Version12.2
OracleRetail Back Office Version14.1
OracleRetail Central Office Version14.1
OracleRetail Integration Bus Version15.0.3
OracleRetail Integration Bus Version16.0.3
OracleRetail Order Broker Version15.0
OracleRetail Order Broker Version16.0
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.89% 0.744
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:N/I:P/A:N
security@pivotal.io 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.