Vulnerability Name:

CVE-2015-5211 (CCN-130673)

Assigned:2015-10-15
Published:2015-10-15
Updated:2022-06-05
Summary:Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.
CVSS v3 Severity:9.6 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
8.3 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-552
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2015-5211

Source: CCN
Type: IBM Security Bulletin 887121 (InfoSphere Information Server)
Multiple vulnerabilities in Spring Framework affect IBM InfoSphere Information Server

Source: XF
Type: UNKNOWN
springframework-cve20155211-file-download(130673)

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20190713 [SECURITY] [DLA 1853-1] libspring-java security update

Source: CCN
Type: Pivotal Security Web site
CVE-2015-5211 RFD Attack in Spring Framework

Source: CONFIRM
Type: Vendor Advisory
https://pivotal.io/security/cve-2015-5211

Source: CCN
Type: IBM Security Bulletin 2017003 (Security Guardium)
IBM Security Guardium is affected by Using Components with Known Vulnerabilities vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6955033 (Security Directory Integrator)
IBM Security Directory Integrator is affected by multiple security vulnerabilities

Source: CCN
Type: IBM Security Bulletin 7001693 (Security Directory Suite VA)
IBM Security Directory Suite is vulnerable to multiple issues

Source: CCN
Type: SpiderLabs Blog, October 30, 2014
Reflected File Download - A New Web Attack Vector

Source: MISC
Type: Exploit, Technical Description
https://www.trustwave.com/Resources/SpiderLabs-Blog/Reflected-File-Download---A-New-Web-Attack-Vector/

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2015-5211

Vulnerable Configuration:Configuration 1:
  • cpe:/a:vmware:spring_framework:3.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:3.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:3.2.8:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:3.2.7:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:3.2.10:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:3.2.9:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:3.2.4:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:3.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:3.2.6:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:3.2.5:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.0.8:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:3.2.14:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.1.6:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:3.2.11:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:3.2.12:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.0.9:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:3.2.13:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.1.7:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:3.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:spring_framework:4.2.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:pivotal:spring_framework:4.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal:spring_framework:3.2.0:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:infosphere_information_server:11.7:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_guardium:10.5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:com.ubuntu.bionic:def:201552110000000
    V
    CVE-2015-5211 on Ubuntu 18.04 LTS (bionic) - medium.
    2017-05-25
    oval:com.ubuntu.artful:def:20155211000
    V
    CVE-2015-5211 on Ubuntu 17.10 (artful) - medium.
    2017-05-25
    oval:com.ubuntu.trusty:def:20155211000
    V
    CVE-2015-5211 on Ubuntu 14.04 LTS (trusty) - medium.
    2017-05-25
    oval:com.ubuntu.xenial:def:201552110000000
    V
    CVE-2015-5211 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-05-25
    oval:com.ubuntu.bionic:def:20155211000
    V
    CVE-2015-5211 on Ubuntu 18.04 LTS (bionic) - medium.
    2017-05-25
    oval:com.ubuntu.xenial:def:20155211000
    V
    CVE-2015-5211 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-05-25
    oval:com.ubuntu.disco:def:201552110000000
    V
    CVE-2015-5211 on Ubuntu 19.04 (disco) - medium.
    2017-05-25
    oval:com.ubuntu.cosmic:def:20155211000
    V
    CVE-2015-5211 on Ubuntu 18.10 (cosmic) - medium.
    2017-05-25
    oval:com.ubuntu.cosmic:def:201552110000000
    V
    CVE-2015-5211 on Ubuntu 18.10 (cosmic) - medium.
    2017-05-25
    oval:com.ubuntu.precise:def:20155211000
    V
    CVE-2015-5211 on Ubuntu 12.04 LTS (precise) - medium.
    2015-12-31
    BACK
    vmware spring framework 3.2.2
    vmware spring framework 3.2.1
    vmware spring framework 3.2.8
    vmware spring framework 3.2.7
    vmware spring framework 3.2.10
    vmware spring framework 3.2.9
    vmware spring framework 3.2.4
    vmware spring framework 3.2.3
    vmware spring framework 3.2.6
    vmware spring framework 3.2.5
    vmware spring framework 4.0.1
    vmware spring framework 4.0.6
    vmware spring framework 4.0.8
    vmware spring framework 3.2.14
    vmware spring framework 4.2.1
    vmware spring framework 4.1.6
    vmware spring framework 4.0.2
    vmware spring framework 4.0.3
    vmware spring framework 4.0.4
    vmware spring framework 4.0.5
    vmware spring framework 3.2.11
    vmware spring framework 3.2.12
    vmware spring framework 4.1.1
    vmware spring framework 4.1.2
    vmware spring framework 4.1.3
    vmware spring framework 4.0.7
    vmware spring framework 4.0.9
    vmware spring framework 3.2.13
    vmware spring framework 4.1.5
    vmware spring framework 4.1.7
    vmware spring framework 4.1.4
    vmware spring framework 3.2.0
    vmware spring framework 4.1.0
    vmware spring framework 4.0.0
    vmware spring framework 4.2.0
    debian debian linux 8.0
    pivotal spring framework 4.0.0
    pivotal spring framework 3.2.0
    ibm infosphere information server 11.7
    ibm security guardium 10.5