V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2015-5211
DEB
Critical

Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to…

CVSS
9.6
Critical
EPSS
0.03
p83
Published
2015-01-01
Updated
2015-01-01
Description

Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.

Tags · CWE
Pre-auth
CWE-552
CAPEC-150
CAPEC-639
Affected products
Debian_linux
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Timeline
2015-01-01
Published
2015-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.026 · p83
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-150 · CWE-552
└ via CAPEC-639 · CWE-552
└ via CAPEC-150 · CWE-552
└ via CAPEC-150 · CWE-552
└ via CAPEC-150 · CWE-552
└ via CAPEC-639 · CWE-552
└ via CAPEC-639 · CWE-552
└ via CAPEC-639 · CWE-552
└ via CAPEC-639 · CWE-552
└ via CAPEC-150 · CWE-552
└ via CAPEC-150 · CWE-552
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
libspring-javaTracked
libspring-javaTracked
libspring-javaTracked
libspring-javaTracked
libspring-javaTracked
libspring-javaTracked
libspring-javaTracked
libspring-javaTracked
libspring-javaTracked
libspring-javaTracked
libspring-javaTracked
libspring-javaTracked
libspring-javaTracked
libspring-javaTracked
libspring-javaTracked
libspring-javaTracked
libspring-javaTracked
debian_linux*Tracked
spring_framework*Tracked
Source databases
DEB
CVE
UBU