CVE-2020-5421
RFD Protection Bypass via jsessionid
Severity Score
6.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
En Spring Framework versiones 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28 y versiones anteriores no compatibles, las protecciones contra ataques RFD del CVE-2015 -5211 puede ser omitidas según el navegador usado mediante el uso de un parámetro de ruta jsessionid
In Spring Framework, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-01-03 CVE Reserved
- 2020-09-19 CVE Published
- 2021-01-10 First Exploit
- 2024-09-10 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (27)
URL | Date | SRC |
---|---|---|
https://github.com/pandaMingx/CVE-2020-5421 | 2021-01-10 |
URL | Date | SRC |
---|---|---|
https://www.oracle.com//security-alerts/cpujul2021.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpuApr2021.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpuapr2022.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpujan2021.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpujan2022.html | 2023-11-07 |
URL | Date | SRC |
---|---|---|
https://tanzu.vmware.com/security/cve-2020-5421 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2020-5421 | 2021-08-11 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1881158 | 2021-08-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vmware Search vendor "Vmware" | Spring Framework Search vendor "Vmware" for product "Spring Framework" | < 4.3.29 Search vendor "Vmware" for product "Spring Framework" and version " < 4.3.29" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Spring Framework Search vendor "Vmware" for product "Spring Framework" | >= 5.0.0 < 5.0.19 Search vendor "Vmware" for product "Spring Framework" and version " >= 5.0.0 < 5.0.19" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Spring Framework Search vendor "Vmware" for product "Spring Framework" | >= 5.1.0 < 5.1.18 Search vendor "Vmware" for product "Spring Framework" and version " >= 5.1.0 < 5.1.18" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Spring Framework Search vendor "Vmware" for product "Spring Framework" | >= 5.2.0 < 5.2.9 Search vendor "Vmware" for product "Spring Framework" and version " >= 5.2.0 < 5.2.9" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Commerce Guided Search Search vendor "Oracle" for product "Commerce Guided Search" | 11.3.2 Search vendor "Oracle" for product "Commerce Guided Search" and version "11.3.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Brm Search vendor "Oracle" for product "Communications Brm" | 11.3.0.9 Search vendor "Oracle" for product "Communications Brm" and version "11.3.0.9" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Brm Search vendor "Oracle" for product "Communications Brm" | 12.0.0.3 Search vendor "Oracle" for product "Communications Brm" and version "12.0.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Design Studio Search vendor "Oracle" for product "Communications Design Studio" | 7.3.4 Search vendor "Oracle" for product "Communications Design Studio" and version "7.3.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Design Studio Search vendor "Oracle" for product "Communications Design Studio" | 7.3.5 Search vendor "Oracle" for product "Communications Design Studio" and version "7.3.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Design Studio Search vendor "Oracle" for product "Communications Design Studio" | 7.4.0 Search vendor "Oracle" for product "Communications Design Studio" and version "7.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Session Report Manager Search vendor "Oracle" for product "Communications Session Report Manager" | >= 8.2.1 <= 8.2.2.1 Search vendor "Oracle" for product "Communications Session Report Manager" and version " >= 8.2.1 <= 8.2.2.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.3.4 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.3.5 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Endeca Information Discovery Integrator Search vendor "Oracle" for product "Endeca Information Discovery Integrator" | 3.2.0 Search vendor "Oracle" for product "Endeca Information Discovery Integrator" and version "3.2.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Data Quality Search vendor "Oracle" for product "Enterprise Data Quality" | 12.2.1.3.0 Search vendor "Oracle" for product "Enterprise Data Quality" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Data Quality Search vendor "Oracle" for product "Enterprise Data Quality" | 12.2.1.4.0 Search vendor "Oracle" for product "Enterprise Data Quality" and version "12.2.1.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Financial Services Analytical Applications Infrastructure Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure" | >= 8.0.6 <= 8.1.0 Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure" and version " >= 8.0.6 <= 8.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Flexcube Private Banking Search vendor "Oracle" for product "Flexcube Private Banking" | 12.0.0 Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Flexcube Private Banking Search vendor "Oracle" for product "Flexcube Private Banking" | 12.1.0 Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Fusion Middleware Search vendor "Oracle" for product "Fusion Middleware" | 12.2.1.3.0 Search vendor "Oracle" for product "Fusion Middleware" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Fusion Middleware Search vendor "Oracle" for product "Fusion Middleware" | 12.2.1.4.0 Search vendor "Oracle" for product "Fusion Middleware" and version "12.2.1.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Goldengate Application Adapters Search vendor "Oracle" for product "Goldengate Application Adapters" | 19.1.0.0.0 Search vendor "Oracle" for product "Goldengate Application Adapters" and version "19.1.0.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Healthcare Master Person Index Search vendor "Oracle" for product "Healthcare Master Person Index" | 4.0.2.5 Search vendor "Oracle" for product "Healthcare Master Person Index" and version "4.0.2.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Hyperion Infrastructure Technology Search vendor "Oracle" for product "Hyperion Infrastructure Technology" | 11.1.2.4 Search vendor "Oracle" for product "Hyperion Infrastructure Technology" and version "11.1.2.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Policy Administration Search vendor "Oracle" for product "Insurance Policy Administration" | >= 11.1.0 <= 11.3.0 Search vendor "Oracle" for product "Insurance Policy Administration" and version " >= 11.1.0 <= 11.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Policy Administration Search vendor "Oracle" for product "Insurance Policy Administration" | 10.2 Search vendor "Oracle" for product "Insurance Policy Administration" and version "10.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Policy Administration Search vendor "Oracle" for product "Insurance Policy Administration" | 10.2.4 Search vendor "Oracle" for product "Insurance Policy Administration" and version "10.2.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Policy Administration Search vendor "Oracle" for product "Insurance Policy Administration" | 11.0.2 Search vendor "Oracle" for product "Insurance Policy Administration" and version "11.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | >= 11.1.0 <= 11.3.0 Search vendor "Oracle" for product "Insurance Rules Palette" and version " >= 11.1.0 <= 11.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 10.2.0 Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.2.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 10.2.4 Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.2.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 11.0.2 Search vendor "Oracle" for product "Insurance Rules Palette" and version "11.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Enterprise Monitor Search vendor "Oracle" for product "Mysql Enterprise Monitor" | <= 8.0.22 Search vendor "Oracle" for product "Mysql Enterprise Monitor" and version " <= 8.0.22" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Enterprise Monitor Search vendor "Oracle" for product "Mysql Enterprise Monitor" | 8.0.23 Search vendor "Oracle" for product "Mysql Enterprise Monitor" and version "8.0.23" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Gateway Search vendor "Oracle" for product "Primavera Gateway" | >= 16.2.0 <= 16.2.11 Search vendor "Oracle" for product "Primavera Gateway" and version " >= 16.2.0 <= 16.2.11" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Gateway Search vendor "Oracle" for product "Primavera Gateway" | >= 17.12.0 <= 17.12.9 Search vendor "Oracle" for product "Primavera Gateway" and version " >= 17.12.0 <= 17.12.9" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Gateway Search vendor "Oracle" for product "Primavera Gateway" | >= 18.8.0 <= 18.8.10 Search vendor "Oracle" for product "Primavera Gateway" and version " >= 18.8.0 <= 18.8.10" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Gateway Search vendor "Oracle" for product "Primavera Gateway" | >= 19.12.0 <= 19.12.10 Search vendor "Oracle" for product "Primavera Gateway" and version " >= 19.12.0 <= 19.12.10" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera P6 Enterprise Project Portfolio Management Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" | >= 16.1.0 <= 16.2.20 Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" and version " >= 16.1.0 <= 16.2.20" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera P6 Enterprise Project Portfolio Management Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" | >= 17.1.0 <= 17.12.19 Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" and version " >= 17.1.0 <= 17.12.19" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera P6 Enterprise Project Portfolio Management Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" | >= 18.1.0 <= 18.8.21 Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" and version " >= 18.1.0 <= 18.8.21" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera P6 Enterprise Project Portfolio Management Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" | >= 19.12.0 <= 19.12.10 Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" and version " >= 19.12.0 <= 19.12.10" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Assortment Planning Search vendor "Oracle" for product "Retail Assortment Planning" | 16.0.3.0 Search vendor "Oracle" for product "Retail Assortment Planning" and version "16.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Bulk Data Integration Search vendor "Oracle" for product "Retail Bulk Data Integration" | 16.0.3.0 Search vendor "Oracle" for product "Retail Bulk Data Integration" and version "16.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Customer Engagement Search vendor "Oracle" for product "Retail Customer Engagement" | >= 16.0 <= 19.0 Search vendor "Oracle" for product "Retail Customer Engagement" and version " >= 16.0 <= 19.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Customer Management And Segmentation Foundation Search vendor "Oracle" for product "Retail Customer Management And Segmentation Foundation" | >= 16.0 <= 19.0 Search vendor "Oracle" for product "Retail Customer Management And Segmentation Foundation" and version " >= 16.0 <= 19.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 14.1.3 Search vendor "Oracle" for product "Retail Financial Integration" and version "14.1.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 15.0.3 Search vendor "Oracle" for product "Retail Financial Integration" and version "15.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 16.0.3 Search vendor "Oracle" for product "Retail Financial Integration" and version "16.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 14.1.3 Search vendor "Oracle" for product "Retail Integration Bus" and version "14.1.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 15.0.3 Search vendor "Oracle" for product "Retail Integration Bus" and version "15.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 16.0.3 Search vendor "Oracle" for product "Retail Integration Bus" and version "16.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Invoice Matching Search vendor "Oracle" for product "Retail Invoice Matching" | 14.0 Search vendor "Oracle" for product "Retail Invoice Matching" and version "14.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Invoice Matching Search vendor "Oracle" for product "Retail Invoice Matching" | 14.1 Search vendor "Oracle" for product "Retail Invoice Matching" and version "14.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Merchandising System Search vendor "Oracle" for product "Retail Merchandising System" | 16.0.3 Search vendor "Oracle" for product "Retail Merchandising System" and version "16.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Order Broker Search vendor "Oracle" for product "Retail Order Broker" | 15.0 Search vendor "Oracle" for product "Retail Order Broker" and version "15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Order Broker Search vendor "Oracle" for product "Retail Order Broker" | 16.0 Search vendor "Oracle" for product "Retail Order Broker" and version "16.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 14.1 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "14.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Returns Management Search vendor "Oracle" for product "Retail Returns Management" | 14.1 Search vendor "Oracle" for product "Retail Returns Management" and version "14.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Service Backbone Search vendor "Oracle" for product "Retail Service Backbone" | 14.1.3 Search vendor "Oracle" for product "Retail Service Backbone" and version "14.1.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Service Backbone Search vendor "Oracle" for product "Retail Service Backbone" | 15.0.3 Search vendor "Oracle" for product "Retail Service Backbone" and version "15.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Service Backbone Search vendor "Oracle" for product "Retail Service Backbone" | 16.0.3 Search vendor "Oracle" for product "Retail Service Backbone" and version "16.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 15.0.4 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "15.0.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 16.0.6 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "16.0.6" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 17.0.4 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "17.0.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 18.0.3 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "18.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 19.0.2 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "19.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Storagetek Acsls Search vendor "Oracle" for product "Storagetek Acsls" | 8.5.1 Search vendor "Oracle" for product "Storagetek Acsls" and version "8.5.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Storagetek Tape Analytics Sw Tool Search vendor "Oracle" for product "Storagetek Tape Analytics Sw Tool" | 2.3 Search vendor "Oracle" for product "Storagetek Tape Analytics Sw Tool" and version "2.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 10.3.6.0.0 Search vendor "Oracle" for product "Weblogic Server" and version "10.3.6.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 12.1.3.0.0 Search vendor "Oracle" for product "Weblogic Server" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 12.2.1.3.0 Search vendor "Oracle" for product "Weblogic Server" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 12.2.1.4.0 Search vendor "Oracle" for product "Weblogic Server" and version "12.2.1.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 14.1.1.0.0 Search vendor "Oracle" for product "Weblogic Server" and version "14.1.1.0.0" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Oncommand Insight Search vendor "Netapp" for product "Oncommand Insight" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Snap Creator Framework Search vendor "Netapp" for product "Snap Creator Framework" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Snapcenter Search vendor "Netapp" for product "Snapcenter" | - | - |
Affected
|