7.8

CVE-2021-22118

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMwareSpring Framework Version >= 5.2.0 < 5.2.15
VMwareSpring Framework Version >= 5.3.0 < 5.3.7
OracleCommerce Guided Search Version11.3.2
OracleCommunications Diameter Intelligence Hub Version >= 8.0.0 <= 8.1.0
OracleCommunications Diameter Intelligence Hub Version >= 8.2.0 <= 8.2.3
OracleCommunications Element Manager Version >= 8.2.0 <= 8.2.4.0
OracleCommunications Session Report Manager Version >= 8.0.0 <= 8.2.4.0
OracleCommunications Session Route Manager Version >= 8.0.0 <= 8.2.4.0
OracleDocumaker Version >= 12.6.0 <= 12.6.4
OracleEnterprise Data Quality Version12.2.1.3.0
OracleEnterprise Data Quality Version12.2.1.4.0
OracleInsurance Policy Administration Version >= 11.0 <= 11.3.1
OracleInsurance Rules Palette Version11.0.2
OracleInsurance Rules Palette Version11.1.0
OracleInsurance Rules Palette Version11.2.7
OracleInsurance Rules Palette Version11.3.0
OracleInsurance Rules Palette Version11.3.1
OracleMysql Enterprise Monitor Version <= 8.0.25
OracleRetail Financial Integration Version14.1.3.2
OracleRetail Financial Integration Version15.0.3.1
OracleRetail Integration Bus Version14.1.3.2
OracleRetail Integration Bus Version15.0.3.1
OracleRetail Integration Bus Version16.0.3
OracleRetail Order Broker Version16.0
OracleUtilities Testing Accelerator Version6.0.0.1.1
OracleUtilities Testing Accelerator Version6.0.0.2.2
OracleUtilities Testing Accelerator Version6.0.0.3.1
NetappHci Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.412
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.