7.8
CVE-2021-22118
- EPSS 0.19%
- Published 27.05.2021 15:15:07
- Last modified 21.11.2024 05:49:32
- Source security@vmware.com
- Teams watchlist Login
- Open Login
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
Data is provided by the National Vulnerability Database (NVD)
VMware ≫ Spring Framework Version >= 5.2.0 < 5.2.15
VMware ≫ Spring Framework Version >= 5.3.0 < 5.3.7
Oracle ≫ Commerce Guided Search Version11.3.2
Oracle ≫ Communications Brm - Elastic Charging Engine Version12.0.0.3
Oracle ≫ Communications Cloud Native Core Binding Support Function Version1.9.0
Oracle ≫ Communications Cloud Native Core Policy Version1.14.0
Oracle ≫ Communications Cloud Native Core Service Communication Proxy Version1.14.0
Oracle ≫ Communications Cloud Native Core Unified Data Repository Version1.14.0
Oracle ≫ Communications Diameter Intelligence Hub Version >= 8.0.0 <= 8.1.0
Oracle ≫ Communications Diameter Intelligence Hub Version >= 8.2.0 <= 8.2.3
Oracle ≫ Communications Element Manager Version >= 8.2.0 <= 8.2.4.0
Oracle ≫ Communications Interactive Session Recorder Version6.4
Oracle ≫ Communications Network Integrity Version7.3.6
Oracle ≫ Communications Session Report Manager Version >= 8.0.0 <= 8.2.4.0
Oracle ≫ Communications Session Route Manager Version >= 8.0.0 <= 8.2.4.0
Oracle ≫ Communications Unified Inventory Management Version7.4.1
Oracle ≫ Communications Unified Inventory Management Version7.4.2
Oracle ≫ Communications Unified Inventory Management Version7.5.0
Oracle ≫ Enterprise Data Quality Version12.2.1.3.0
Oracle ≫ Enterprise Data Quality Version12.2.1.4.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version >= 8.0.8 <= 8.1.1
Oracle ≫ Healthcare Data Repository Version8.1.0
Oracle ≫ Insurance Policy Administration Version >= 11.0 <= 11.3.1
Oracle ≫ Insurance Rules Palette Version11.0.2
Oracle ≫ Insurance Rules Palette Version11.1.0
Oracle ≫ Insurance Rules Palette Version11.2.7
Oracle ≫ Insurance Rules Palette Version11.3.0
Oracle ≫ Insurance Rules Palette Version11.3.1
Oracle ≫ Mysql Enterprise Monitor Version <= 8.0.25
Oracle ≫ Retail Assortment Planning Version16.0
Oracle ≫ Retail Customer Management And Segmentation Foundation Version >= 16.0 <= 19.0
Oracle ≫ Retail Financial Integration Version14.1.3.2
Oracle ≫ Retail Financial Integration Version15.0.3.1
Oracle ≫ Retail Financial Integration Version16.0.3
Oracle ≫ Retail Integration Bus Version14.1.3.2
Oracle ≫ Retail Integration Bus Version15.0.3.1
Oracle ≫ Retail Integration Bus Version16.0.3
Oracle ≫ Retail Merchandising System Version19.0.1
Oracle ≫ Retail Order Broker Version16.0
Oracle ≫ Retail Predictive Application Server Version14.1.3
Oracle ≫ Retail Predictive Application Server Version15.0.3
Oracle ≫ Retail Predictive Application Server Version16.0.3
Oracle ≫ Utilities Testing Accelerator Version6.0.0.1.1
Oracle ≫ Utilities Testing Accelerator Version6.0.0.2.2
Oracle ≫ Utilities Testing Accelerator Version6.0.0.3.1
Netapp ≫ Management Services For Element Software Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.19% | 0.412 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-668 Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.