Vulnerability Name:

CVE-2014-3625 (CCN-99872)

Assigned:2014-11-14
Published:2014-11-14
Updated:2022-04-11
Summary:Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-22
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2014-3625

Source: REDHAT
Type: Third Party Advisory
RHSA-2015:0236

Source: REDHAT
Type: Third Party Advisory
RHSA-2015:0720

Source: CCN
Type: IBM Security Bulletin 1997872 (Security Guardium)
OpenSource GoPivotal Spring Framework Vulnerabilities affect IBM Security Guardium (CVE-2014-3578, CVE-2014-3625)

Source: CCN
Type: IBM Security Bulletin 1999040 (Tivoli Application Dependency Discovery Manager)
Pivotal Spring Framework vulnerabilities affect IBM Tivoli Application Dependency Discovery Manager (TADDM)

Source: CCN
Type: IBM Security Bulletin 1999395 (Security QRadar SIEM)
Pivotal Spring Framework as used in IBM QRadar SIEM is vulnerable to various CVE's

Source: CCN
Type: IBM Security Bulletin 2002110 (Interact)
Vulnerability in Pivotal Spring Framework affects IBM Marketing Software products suite (CVE-2014-3625)

Source: CCN
Type: IBM Security Bulletin 2005279 (WebSphere Portal)
Multiple Vulnerabilities affect IBM WebSphere Portal Rich Media Edition

Source: CCN
Type: IBM Security Bulletin 2013753 (Security Guardium Big Data Intelligence)
IBM Security Guardium Big Data Intelligence (SonarG) is vulnerable to using Components with Known Vulnerabilities

Source: CCN
Type: Pivotal Web site
CVE-2014-3625 Directory Traversal in Spring Framework

Source: CONFIRM
Type: Vendor Advisory
http://www.pivotal.io/security/cve-2014-3625

Source: XF
Type: UNKNOWN
springframework-cve20143625-dir-traversal(99872)

Source: CONFIRM
Type: Third Party Advisory
https://jira.spring.io/browse/SPR-12354

Source: MLIST
Type: UNKNOWN
[debian-lts-announce] 20190713 [SECURITY] [DLA 1853-1] libspring-java security update

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2014-3625

Vulnerable Configuration:Configuration 1:
  • cpe:/a:vmware:spring_framework:*:*:*:*:*:*:*:* (Version >= 3.0.4 and <= 3.0.7)
  • OR cpe:/a:pivotal_software:spring_framework:*:*:*:*:*:*:*:* (Version >= 3.1.0 and <= 3.1.4)
  • OR cpe:/a:pivotal_software:spring_framework:*:*:*:*:*:*:*:* (Version >= 3.2.0 and < 3.2.12)
  • OR cpe:/a:pivotal_software:spring_framework:*:*:*:*:*:*:*:* (Version >= 4.0.0 and < 4.0.8)
  • OR cpe:/a:pivotal_software:spring_framework:*:*:*:*:*:*:*:* (Version >= 4.1.0 and < 4.1.2)

  • Configuration CCN 1:
  • cpe:/a:pivotal:spring_framework:3.2.11:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal:spring_framework:4.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal:spring_framework:4.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal:spring_framework:3.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal:spring_framework:4.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal:spring_framework:4.1.0:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:websphere_portal:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_portal:8.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_application_dependency_discovery_manager:7.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_guardium:9.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_guardium:9.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_guardium:9.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:interact:10.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_guardium_big_data_intelligence:3.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:com.ubuntu.bionic:def:201436250000000
    V
    CVE-2014-3625 on Ubuntu 18.04 LTS (bionic) - medium.
    2014-11-20
    oval:com.ubuntu.artful:def:20143625000
    V
    CVE-2014-3625 on Ubuntu 17.10 (artful) - medium.
    2014-11-20
    oval:com.ubuntu.trusty:def:20143625000
    V
    CVE-2014-3625 on Ubuntu 14.04 LTS (trusty) - medium.
    2014-11-20
    oval:com.ubuntu.xenial:def:201436250000000
    V
    CVE-2014-3625 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-11-20
    oval:com.ubuntu.bionic:def:20143625000
    V
    CVE-2014-3625 on Ubuntu 18.04 LTS (bionic) - medium.
    2014-11-20
    oval:com.ubuntu.xenial:def:20143625000
    V
    CVE-2014-3625 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-11-20
    oval:com.ubuntu.disco:def:201436250000000
    V
    CVE-2014-3625 on Ubuntu 19.04 (disco) - medium.
    2014-11-20
    oval:com.ubuntu.cosmic:def:20143625000
    V
    CVE-2014-3625 on Ubuntu 18.10 (cosmic) - medium.
    2014-11-20
    oval:com.ubuntu.cosmic:def:201436250000000
    V
    CVE-2014-3625 on Ubuntu 18.10 (cosmic) - medium.
    2014-11-20
    oval:com.ubuntu.precise:def:20143625000
    V
    CVE-2014-3625 on Ubuntu 12.04 LTS (precise) - medium.
    2014-11-20
    BACK
    vmware spring framework *
    pivotal_software spring framework *
    pivotal_software spring framework *
    pivotal_software spring framework *
    pivotal_software spring framework *
    pivotal spring framework 3.2.11
    pivotal spring framework 4.0.7
    pivotal spring framework 4.1.1
    pivotal spring framework 3.0.4
    pivotal spring framework 4.0.0
    pivotal spring framework 4.1.0
    ibm websphere portal 8.0
    ibm qradar security information and event manager 7.2
    ibm websphere portal 8.5
    ibm tivoli application dependency discovery manager 7.2.2
    ibm security guardium 9.0
    ibm security guardium 9.1
    ibm security guardium 9.5
    ibm interact 10.0
    ibm security guardium big data intelligence 3.1