5.3

CVE-2022-22968

In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Framework Version < 5.2.0
VMware ≫ Spring Framework Version >= 5.2.0 <= 5.2.20
VMware ≫ Spring Framework Version >= 5.3.0 <= 5.3.18
Netapp ≫ Active Iq Unified Manager Version - SwPlatform linux
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Netapp ≫ Cloud Secure Agent Version -
Netapp ≫ Metrocluster Tiebreaker Version - SwPlatform clustered_data_ontap
Netapp ≫ Snapmanager Version - SwPlatform oracle
Netapp ≫ Snapmanager Version - SwPlatform sap
Oracle ≫ Mysql Enterprise Monitor Version <= 8.0.29
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.67% 0.92
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-178 Improper Handling of Case Sensitivity

The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.

https://www.oracle.com/security-alerts/cpujul2022.html
Third Party Advisory
https://security.netapp.com/advisory/ntap-20220602-0004/
Third Party Advisory
https://tanzu.vmware.com/security/cve-2022-22968
Vendor Advisory