imPC@ndo IT

Tracker / CVE-2021-22118

CVE-2021-22118

High 7.8

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

Affected products and versions

netapp hci
netapp management_services_for_element_software
oracle commerce_guided_search
oracle communications_brm_-_elastic_charging_engine
oracle communications_cloud_native_core_binding_support_function
oracle communications_cloud_native_core_policy
oracle communications_cloud_native_core_security_edge_protection_proxy
oracle communications_cloud_native_core_service_communication_proxy
oracle communications_cloud_native_core_unified_data_repository
oracle communications_diameter_intelligence_hub · 8.0.0 → 8.1.0
oracle communications_diameter_intelligence_hub · 8.2.0 → 8.2.3
oracle communications_element_manager · 8.2.0 → 8.2.4.0
oracle communications_interactive_session_recorder
oracle communications_network_integrity
oracle communications_session_report_manager · 8.0.0 → 8.2.4.0
oracle communications_session_route_manager · 8.0.0 → 8.2.4.0
oracle communications_unified_inventory_management
oracle documaker · 12.6.0 → 12.6.4
oracle enterprise_data_quality
oracle financial_services_analytical_applications_infrastructure · 8.0.8 → 8.1.1
oracle healthcare_data_repository
oracle insurance_policy_administration · 11.0 → 11.3.1
oracle insurance_rules_palette
oracle mysql_enterprise_monitor · … → 8.0.25
oracle retail_assortment_planning
oracle retail_customer_management_and_segmentation_foundation · 16.0 → 19.0
oracle retail_financial_integration
oracle retail_integration_bus
oracle retail_merchandising_system
oracle retail_order_broker
oracle retail_predictive_application_server
oracle utilities_testing_accelerator
vmware spring_framework · 5.2.0 → 5.2.15
vmware spring_framework · 5.3.0 → 5.3.7

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References