A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| vmware | spring_framework | 5.2.20 | - |
| vmware | spring_framework | 5.3.0 - 5.3.18 | - |
| cisco | cx_cloud_agent | 2.1.0 |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
97
Affected Products
18
References
vmware / spring_framework
| - |
| oracle | communications_cloud_native_core_automated_test_suite | - | - |
| oracle | communications_cloud_native_core_automated_test_suite | - | - |
| oracle | communications_cloud_native_core_console | - | - |
| oracle | communications_cloud_native_core_console | - | - |
| oracle | communications_cloud_native_core_network_exposure_function | - | - |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | - | - |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | - | - |
| oracle | communications_cloud_native_core_network_repository_function | - | - |
| oracle | communications_cloud_native_core_network_repository_function | - | - |
| oracle | communications_cloud_native_core_network_slice_selection_function | - | - |
| oracle | communications_cloud_native_core_network_slice_selection_function | - | - |
| oracle | communications_cloud_native_core_network_slice_selection_function | - | - |
| oracle | communications_cloud_native_core_policy | - | - |
| oracle | communications_cloud_native_core_policy | - | - |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | - | - |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | - | - |
| oracle | communications_cloud_native_core_unified_data_repository | - | - |
| oracle | communications_cloud_native_core_unified_data_repository | - | - |
| oracle | communications_policy_management | - | - |
| oracle | financial_services_analytical_applications_infrastructure | - | - |
| oracle | financial_services_analytical_applications_infrastructure | - | - |
| oracle | financial_services_behavior_detection_platform | - | - |
| oracle | financial_services_behavior_detection_platform | - | - |
| oracle | financial_services_behavior_detection_platform | - | - |
| oracle | financial_services_enterprise_case_management | - | - |
| oracle | financial_services_enterprise_case_management | - | - |
| oracle | financial_services_enterprise_case_management | - | - |
| oracle | mysql_enterprise_monitor | 8.0.29 | - |
| oracle | product_lifecycle_analytics | - | - |
| oracle | retail_xstore_point_of_service | - | - |
| oracle | retail_xstore_point_of_service | - | - |
| oracle | sd-wan_edge | - | - |
| oracle | sd-wan_edge | - | - |
| siemens | operation_scheduler | 2.0.4 | - |
| siemens | sipass_integrated | - | - |
| siemens | sipass_integrated | - | - |
| siemens | siveillance_identity | - | - |
| siemens | siveillance_identity | - | - |
| veritas | access_appliance | - | - |
| veritas | access_appliance | - | - |
| veritas | access_appliance | - | - |
| veritas | access_appliance | - | - |
| veritas | access_appliance | - | - |
| veritas | access_appliance | - | - |
| veritas | flex_appliance | - | - |
| veritas | flex_appliance | - | - |
| veritas | flex_appliance | - | - |
| veritas | flex_appliance | - | - |
| veritas | flex_appliance | - | - |
| veritas | netbackup_flex_scale_appliance | - | - |
| veritas | netbackup_flex_scale_appliance | - | - |
| veritas | netbackup_appliance | - | - |
| veritas | netbackup_appliance | - | - |
| veritas | netbackup_appliance | - | - |
| veritas | netbackup_appliance | - | - |
| veritas | netbackup_appliance | - | - |
| veritas | netbackup_appliance | - | - |
| veritas | netbackup_appliance | - | - |
| veritas | netbackup_virtual_appliance | - | - |
| veritas | netbackup_virtual_appliance | - | - |
| veritas | netbackup_virtual_appliance | - | - |
| veritas | netbackup_virtual_appliance | - | - |
| veritas | netbackup_virtual_appliance | - | - |
| veritas | netbackup_virtual_appliance | - | - |
| veritas | netbackup_virtual_appliance | - | - |
| siemens | operation_scheduler | 2.0.4 | - |
| siemens | simatic_speech_assistant_for_machines | 1.2.1 | - |
| siemens | sinec_network_management_system | 1.0.3 | - |
| siemens | sipass_integrated | - | - |
| siemens | sipass_integrated | - | - |
| siemens | siveillance_identity | - | - |
| siemens | siveillance_identity | - | - |
| oracle | commerce_platform | - | - |
| oracle | communications_cloud_native_core_binding_support_function | - | - |
| oracle | communications_unified_inventory_management | - | - |
| oracle | communications_unified_inventory_management | - | - |
| oracle | communications_unified_inventory_management | - | - |
| oracle | retail_bulk_data_integration | - | - |
| oracle | retail_customer_management_and_segmentation_foundation | - | - |
| oracle | retail_customer_management_and_segmentation_foundation | - | - |
| oracle | retail_customer_management_and_segmentation_foundation | - | - |
| oracle | retail_financial_integration | - | - |
| oracle | retail_financial_integration | - | - |
| oracle | retail_financial_integration | - | - |
| oracle | retail_financial_integration | - | - |
| oracle | retail_integration_bus | - | - |
| oracle | retail_integration_bus | - | - |
| oracle | retail_integration_bus | - | - |
| oracle | retail_integration_bus | - | - |
| oracle | retail_merchandising_system | - | - |
| oracle | retail_merchandising_system | - | - |
| oracle | weblogic_server | - | - |
| oracle | weblogic_server | - | - |
| oracle | weblogic_server | - | - |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability
Impact