| Vulnerability Name: | CVE-2014-3578 (CCN-93774) | ||||||||||||||||||||||||||||||||||||||||||||
| Assigned: | 2014-06-13 | ||||||||||||||||||||||||||||||||||||||||||||
| Published: | 2014-06-13 | ||||||||||||||||||||||||||||||||||||||||||||
| Updated: | 2019-07-14 | ||||||||||||||||||||||||||||||||||||||||||||
| Summary: | Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL. | ||||||||||||||||||||||||||||||||||||||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||||||||||||||||||||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||
| Vulnerability Type: | CWE-22 | ||||||||||||||||||||||||||||||||||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2014-3578 Source: CCN Type: JVN#49154900 Spring Framework vulnerable to directory traversal Source: JVN Type: Third Party Advisory, VDB Entry JVN#49154900 Source: JVNDB Type: Third Party Advisory, VDB Entry JVNDB-2014-000054 Source: MISC Type: Vendor Advisory http://pivotal.io/security/cve-2014-3578 Source: REDHAT Type: Third Party Advisory RHSA-2015:0720 Source: CCN Type: IBM Security Bulletin 1997872 (Security Guardium) OpenSource GoPivotal Spring Framework Vulnerabilities affect IBM Security Guardium (CVE-2014-3578, CVE-2014-3625) Source: CCN Type: IBM Security Bulletin 1999040 (Tivoli Application Dependency Discovery Manager) Pivotal Spring Framework vulnerabilities affect IBM Tivoli Application Dependency Discovery Manager (TADDM) Source: CCN Type: IBM Security Bulletin 1999395 (Security QRadar SIEM) Pivotal Spring Framework as used in IBM QRadar SIEM is vulnerable to various CVE's Source: CCN Type: IBM Security Bulletin 2005279 (WebSphere Portal) Multiple Vulnerabilities affect IBM WebSphere Portal Rich Media Edition Source: CCN Type: IBM Security Bulletin 2013753 (Security Guardium Big Data Intelligence) IBM Security Guardium Big Data Intelligence (SonarG) is vulnerable to using Components with Known Vulnerabilities Source: BID Type: Third Party Advisory, VDB Entry 68042 Source: CCN Type: BID-68042 Spring Framework Unspecified Directory Traversal Vulnerability Source: CONFIRM Type: Issue Tracking, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=1131882 Source: XF Type: UNKNOWN spring-framework-directory-traversal(93774) Source: MLIST Type: UNKNOWN [debian-lts-announce] 20190713 [SECURITY] [DLA 1853-1] libspring-java security update Source: CCN Type: Pivotal Web site Spring Framework Source: REDHAT Type: Third Party Advisory RHSA-2015:0234 Source: REDHAT Type: Third Party Advisory RHSA-2015:0235 Source: CCN Type: IBM Security Bulletin 3106029 (StoredIQ) Multiple Vulnerabilities identified in IBM StoredIQ Source: CCN Type: IBM Security Bulletin 6244618 (Cloud Pak System) Multiple vulnerabilities in Open Source used in IBM Cloud Pak System | ||||||||||||||||||||||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||||||||||||||||||||||