SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.
| Software | From | Fixed in |
|---|---|---|
| oracle / fusion_middleware | 11.1.1.8.0 | 11.1.1.8.0.x |
| oracle / fusion_middleware | 7.6.2 | 7.6.2.x |
| oracle / fusion_middleware | 11.1.1.6.1 | 11.1.1.6.1.x |
| springsource / spring_framework | 2.5.0 | 2.5.0.x |
| springsource / spring_framework | 3.0.1 | 3.0.1.x |
| springsource / spring_framework | 2.5.3 | 2.5.3.x |
| springsource / spring_framework | 3.0.2 | 3.0.2.x |
| springsource / spring_framework | 2.5.5 | 2.5.5.x |
| springsource / spring_framework | 2.5.6 | 2.5.6.x |
| springsource / spring_framework | 2.5.4 | 2.5.4.x |
| springsource / spring_framework | 2.5.2 | 2.5.2.x |
| springsource / spring_framework | 2.5.7 | 2.5.7.x |
| springsource / spring_framework | 3.0.0 | 3.0.0.x |
| springsource / spring_framework | 2.5.1 | 2.5.1.x |
org.springframework / spring
|
2.5.0 | 2.5.7 |
org.springframework / spring
|
3.0.0 | 3.0.3 |