Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2020-5398

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 7.6
  • AV:N/AC:H/Au:N/C:C/I:C/A:C
Software From Fixed in
vmware / spring_framework 5.2.0 5.2.3
vmware / spring_framework 5.0.0 5.0.16
vmware / spring_framework 5.1.0 5.1.13
oracle / flexcube_private_banking 12.1.0 12.1.0.x
oracle / insurance_policy_administration_j2ee 10.2.0 10.2.0.x
oracle / flexcube_private_banking 12.0.0 12.0.0.x
oracle / insurance_rules_palette 10.2.0 10.2.0.x
oracle / retail_service_backbone 15.0 15.0.x
oracle / retail_back_office 14.1 14.1.x
oracle / weblogic_server 12.2.1.3.0 12.2.1.3.0.x
oracle / application_testing_suite 13.3.0.1 13.3.0.1.x
oracle / retail_order_broker 15.0 15.0.x
oracle / retail_order_broker 16.0 16.0.x
oracle / retail_returns_management 14.1 14.1.x
oracle / retail_central_office 14.1 14.1.x
oracle / retail_assortment_planning 15.0 15.0.x
oracle / retail_point-of-service 14.1 14.1.x
oracle / retail_predictive_application_server 15.0.3 15.0.3.x
oracle / retail_assortment_planning 16.0 16.0.x
oracle / retail_financial_integration 15.0 15.0.x
oracle / retail_financial_integration 16.0 16.0.x
oracle / communications_policy_management 12.5.0 12.5.0.x
oracle / weblogic_server 12.2.1.4.0 12.2.1.4.0.x
oracle / mysql 8.0.0 8.0.20.x
oracle / rapid_planning 12.1 12.1.x
oracle / rapid_planning 12.2 12.2.x
oracle / communications_element_manager 8.2.0 8.2.0.x
oracle / communications_element_manager 8.2.1 8.2.1.x
oracle / communications_element_manager 8.1.1 8.1.1.x
oracle / communications_diameter_signaling_router 8.0.0 8.2.2.x
oracle / retail_predictive_application_server 14.1.3.0 14.1.3.0.x
oracle / retail_bulk_data_integration 16.0.3.0 16.0.3.0.x
oracle / retail_predictive_application_server 16.0.3.0 16.0.3.0.x
oracle / communications_session_report_manager 8.1.1 8.1.1.x
oracle / communications_session_report_manager 8.2.0 8.2.0.x
oracle / communications_session_report_manager 8.2.1 8.2.1.x
oracle / communications_session_route_manager 8.1.1 8.1.1.x
oracle / communications_session_route_manager 8.2.0 8.2.0.x
oracle / communications_session_route_manager 8.2.1 8.2.1.x
oracle / retail_service_backbone 16.0 16.0.x
oracle / retail_integration_bus 15.0.3 15.0.3.x
oracle / retail_predictive_application_server 14.0.3 14.0.3.x
oracle / retail_integration_bus 16.0.3 16.0.3.x
oracle / mysql 4.0.0 4.0.12.x
oracle / insurance_rules_palette 10.2.4 10.2.4.x
oracle / insurance_rules_palette 11.0.2 11.0.2.x
oracle / insurance_rules_palette 11.1.0 11.1.0.x
oracle / insurance_rules_palette 11.2.0 11.2.0.x
oracle / insurance_policy_administration_j2ee 10.2.4 10.2.4.x
oracle / insurance_policy_administration_j2ee 11.0.2 11.0.2.x
oracle / insurance_policy_administration_j2ee 11.1.0 11.1.0.x
oracle / insurance_policy_administration_j2ee 11.2.0 11.2.0.x
oracle / healthcare_master_person_index 4.0.2 4.0.2.x
oracle / communications_billing_and_revenue_management_elastic_charging_engine 11.3 11.3.x
oracle / communications_billing_and_revenue_management_elastic_charging_engine 12.0 12.0.x
oracle / financial_services_regulatory_reporting_with_agilereporter 8.0.9.2.0 8.0.9.2.0.x
oracle / enterprise_manager_base_platform 13.2.1.0 13.2.1.0.x
oracle / insurance_policy_administration_j2ee 11.2.2.0 11.2.2.0.x
oracle / communications_cloud_native_core_policy 1.5.0 1.5.0.x
oracle / siebel_engineering_-_installer_&_deployment - 2.1.1.x
oracle / insurance_calculation_engine 11.0.0 11.3.1.x
org.springframework / spring-webmvc 5.2.0.RELEASE 5.2.3.RELEASE
org.springframework / spring-webmvc 5.1.0.RELEASE 5.1.13.RELEASE
org.springframework / spring-webmvc 5.0.0.RELEASE 5.0.16.RELEASE
org.springframework / spring-webflux 5.2.0.RELEASE 5.2.3.RELEASE
org.springframework / spring-webflux 5.1.0.RELEASE 5.1.13.RELEASE
org.springframework / spring-webflux 5.0.0.RELEASE 5.0.16.RELEASE