7.8

CVE-2021-22118

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Framework Version >= 5.2.0 < 5.2.15
VMware ≫ Spring Framework Version >= 5.3.0 < 5.3.7
Oracle ≫ Commerce Guided Search Version 11.3.2
Oracle ≫ Communications Diameter Intelligence Hub Version >= 8.0.0 <= 8.1.0
Oracle ≫ Communications Diameter Intelligence Hub Version >= 8.2.0 <= 8.2.3
Oracle ≫ Communications Element Manager Version >= 8.2.0 <= 8.2.4.0
Oracle ≫ Communications Session Report Manager Version >= 8.0.0 <= 8.2.4.0
Oracle ≫ Communications Session Route Manager Version >= 8.0.0 <= 8.2.4.0
Oracle ≫ Documaker Version >= 12.6.0 <= 12.6.4
Oracle ≫ Enterprise Data Quality Version 12.2.1.3.0
Oracle ≫ Enterprise Data Quality Version 12.2.1.4.0
Oracle ≫ Insurance Policy Administration Version >= 11.0 <= 11.3.1
Oracle ≫ Insurance Rules Palette Version 11.0.2
Oracle ≫ Insurance Rules Palette Version 11.1.0
Oracle ≫ Insurance Rules Palette Version 11.2.7
Oracle ≫ Insurance Rules Palette Version 11.3.0
Oracle ≫ Insurance Rules Palette Version 11.3.1
Oracle ≫ Mysql Enterprise Monitor Version <= 8.0.25
Oracle ≫ Retail Financial Integration Version 14.1.3.2
Oracle ≫ Retail Financial Integration Version 15.0.3.1
Oracle ≫ Retail Integration Bus Version 14.1.3.2
Oracle ≫ Retail Integration Bus Version 15.0.3.1
Oracle ≫ Retail Integration Bus Version 16.0.3
Oracle ≫ Retail Merchandising System Version 19.0.1
Oracle ≫ Retail Order Broker Version 16.0
Oracle ≫ Utilities Testing Accelerator Version 6.0.0.1.1
Oracle ≫ Utilities Testing Accelerator Version 6.0.0.2.2
Oracle ≫ Utilities Testing Accelerator Version 6.0.0.3.1
Netapp ≫ Hci Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.312
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

https://www.oracle.com/security-alerts/cpuapr2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html
Patch
Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
Patch
Third Party Advisory
https://security.netapp.com/advisory/ntap-20210713-0005/
Third Party Advisory
https://tanzu.vmware.com/security/cve-2021-22118
Third Party Advisory