Tracker / CVE-2021-22118
CVE-2021-22118
High 7.8
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
Affected products and versions
| netapp | hci |
|---|---|
| netapp | management_services_for_element_software |
| oracle | commerce_guided_search |
| oracle | communications_brm_-_elastic_charging_engine |
| oracle | communications_cloud_native_core_binding_support_function |
| oracle | communications_cloud_native_core_policy |
| oracle | communications_cloud_native_core_security_edge_protection_proxy |
| oracle | communications_cloud_native_core_service_communication_proxy |
| oracle | communications_cloud_native_core_unified_data_repository |
| oracle | communications_diameter_intelligence_hub · 8.0.0 → 8.1.0 |
| oracle | communications_diameter_intelligence_hub · 8.2.0 → 8.2.3 |
| oracle | communications_element_manager · 8.2.0 → 8.2.4.0 |
| oracle | communications_interactive_session_recorder |
| oracle | communications_network_integrity |
| oracle | communications_session_report_manager · 8.0.0 → 8.2.4.0 |
| oracle | communications_session_route_manager · 8.0.0 → 8.2.4.0 |
| oracle | communications_unified_inventory_management |
| oracle | documaker · 12.6.0 → 12.6.4 |
| oracle | enterprise_data_quality |
| oracle | financial_services_analytical_applications_infrastructure · 8.0.8 → 8.1.1 |
| oracle | healthcare_data_repository |
| oracle | insurance_policy_administration · 11.0 → 11.3.1 |
| oracle | insurance_rules_palette |
| oracle | mysql_enterprise_monitor · … → 8.0.25 |
| oracle | retail_assortment_planning |
| oracle | retail_customer_management_and_segmentation_foundation · 16.0 → 19.0 |
| oracle | retail_financial_integration |
| oracle | retail_integration_bus |
| oracle | retail_merchandising_system |
| oracle | retail_order_broker |
| oracle | retail_predictive_application_server |
| oracle | utilities_testing_accelerator |
| vmware | spring_framework · 5.2.0 → 5.2.15 |
| vmware | spring_framework · 5.3.0 → 5.3.7 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.