CVE-2015-5211

Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:spring_framework:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.7:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.8:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.9:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.10:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.11:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.12:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.13:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.14:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.7:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.8:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.9:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.1.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.1.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.1.7:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.2.1:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

05 Jun 2022, 03:44

Type Values Removed Values Added
CWE CWE-20 CWE-552
First Time Debian debian Linux
Debian
References (MLIST) https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html - (MLIST) https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html - Mailing List, Third Party Advisory
CPE cpe:2.3:a:pivotal_software:spring_framework:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.2.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.1.0:*:*:*:*:*:*:*
CVSS v2 : 9.3
v3 : 8.6
v2 : 9.3
v3 : 9.6

11 Apr 2022, 17:18

Type Values Removed Values Added
CPE cpe:2.3:a:pivotal_software:spring_framework:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.6:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.12:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.9:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.7:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.1.7:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.11:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.7:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.8:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.5:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.9:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.1.5:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.1.6:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.13:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.14:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.10:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.6:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:spring_framework:3.2.8:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.8:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.13:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.8:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.10:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.7:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.1.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.9:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.12:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.1.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.1.7:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.7:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.11:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:3.2.14:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.0.9:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:4.1.1:*:*:*:*:*:*:*
First Time Vmware
Vmware spring Framework

Information

Published : 2017-05-25 17:29

Updated : 2023-12-10 12:15


NVD link : CVE-2015-5211

Mitre link : CVE-2015-5211

CVE.ORG link : CVE-2015-5211


JSON object : View

Products Affected

vmware

  • spring_framework

debian

  • debian_linux
CWE
CWE-552

Files or Directories Accessible to External Parties