7.8
CVE-2021-22118
- EPSS 0.4%
- Veröffentlicht 27.05.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:32
- Erkennungen
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Framework Version >= 5.2.0 < 5.2.15
VMware ≫ Spring Framework Version >= 5.3.0 < 5.3.7
Oracle ≫ Commerce Guided Search Version 11.3.2
Oracle ≫ Communications Brm - Elastic Charging Engine Version 12.0.0.3
Oracle ≫ Communications Cloud Native Core Binding Support Function Version 1.9.0
Oracle ≫ Communications Cloud Native Core Policy Version 1.14.0
Oracle ≫ Communications Cloud Native Core Service Communication Proxy Version 1.14.0
Oracle ≫ Communications Cloud Native Core Unified Data Repository Version 1.14.0
Oracle ≫ Communications Diameter Intelligence Hub Version >= 8.0.0 <= 8.1.0
Oracle ≫ Communications Diameter Intelligence Hub Version >= 8.2.0 <= 8.2.3
Oracle ≫ Communications Element Manager Version >= 8.2.0 <= 8.2.4.0
Oracle ≫ Communications Interactive Session Recorder Version 6.4
Oracle ≫ Communications Network Integrity Version 7.3.6
Oracle ≫ Communications Session Report Manager Version >= 8.0.0 <= 8.2.4.0
Oracle ≫ Communications Session Route Manager Version >= 8.0.0 <= 8.2.4.0
Oracle ≫ Communications Unified Inventory Management Version 7.4.1
Oracle ≫ Communications Unified Inventory Management Version 7.4.2
Oracle ≫ Communications Unified Inventory Management Version 7.5.0
Oracle ≫ Enterprise Data Quality Version 12.2.1.3.0
Oracle ≫ Enterprise Data Quality Version 12.2.1.4.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version >= 8.0.8 <= 8.1.1
Oracle ≫ Healthcare Data Repository Version 8.1.0
Oracle ≫ Insurance Policy Administration Version >= 11.0 <= 11.3.1
Oracle ≫ Insurance Rules Palette Version 11.0.2
Oracle ≫ Insurance Rules Palette Version 11.1.0
Oracle ≫ Insurance Rules Palette Version 11.2.7
Oracle ≫ Insurance Rules Palette Version 11.3.0
Oracle ≫ Insurance Rules Palette Version 11.3.1
Oracle ≫ Mysql Enterprise Monitor Version <= 8.0.25
Oracle ≫ Retail Assortment Planning Version 16.0
Oracle ≫ Retail Customer Management And Segmentation Foundation Version >= 16.0 <= 19.0
Oracle ≫ Retail Financial Integration Version 14.1.3.2
Oracle ≫ Retail Financial Integration Version 15.0.3.1
Oracle ≫ Retail Financial Integration Version 16.0.3
Oracle ≫ Retail Integration Bus Version 14.1.3.2
Oracle ≫ Retail Integration Bus Version 15.0.3.1
Oracle ≫ Retail Integration Bus Version 16.0.3
Oracle ≫ Retail Merchandising System Version 19.0.1
Oracle ≫ Retail Order Broker Version 16.0
Oracle ≫ Retail Predictive Application Server Version 14.1.3
Oracle ≫ Retail Predictive Application Server Version 15.0.3
Oracle ≫ Retail Predictive Application Server Version 16.0.3
Oracle ≫ Utilities Testing Accelerator Version 6.0.0.1.1
Oracle ≫ Utilities Testing Accelerator Version 6.0.0.2.2
Oracle ≫ Utilities Testing Accelerator Version 6.0.0.3.1
Netapp ≫ Management Services For Element Software Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.312 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-668 Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuoct2021.html
https://www.oracle.com/security-alerts/cpujul2022.html
https://security.netapp.com/advisory/ntap-20210713-0005/
https://tanzu.vmware.com/security/cve-2021-22118