← Back

CVE-2021-22118

nvd nist
Published: May 27, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

Affected (49)

Products: Vmware: Spring Framework · Oracle: Commerce Guided Search, Communications Brm Elastic Charging Engine, Communications Cloud Native Core Binding Support Function, Communications Cloud Native Core Policy, Communications Cloud Native Core Security Edge Protection Proxy, Communications Cloud Native Core Service Communication Proxy, Communications Cloud Native Core Unified Data Repository, Communications Diameter Intelligence Hub, Communications Element Manager, Communications Interactive Session Recorder, Communications Network Integrity, Communications Session Report Manager, Communications Session Route Manager, Communications Unified Inventory Management, Documaker, Enterprise Data Quality, Financial Services Analytical Applications Infrastructure, Healthcare Data Repository, Insurance Policy Administration, Insurance Rules Palette, Mysql Enterprise Monitor, Retail Assortment Planning, Retail Customer Management And Segmentation Foundation, Retail Financial Integration, Retail Integration Bus, Retail Merchandising System, Retail Order Broker, Retail Predictive Application Server, Utilities Testing Accelerator · Netapp: Hci, Management Services For Element Software
1 product
Spring Framework
29 products
Commerce Guided Search
Communications Element Manager
Communications Network Integrity
Documaker
Enterprise Data Quality
Healthcare Data Repository
Insurance Policy Administration
Insurance Rules Palette
Mysql Enterprise Monitor
Retail Assortment Planning
Retail Financial Integration
Retail Integration Bus
Retail Merchandising System
Retail Order Broker
Utilities Testing Accelerator
2 products
Hci
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
From 5.2.0 to 5.2.15
From 5.3.0 to 5.3.7
Configuration B
45 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.3.2
Version 12.0.0.3
Version 1.9.0
Version 1.14.0
Version 1.6.0
Version 1.14.0
Version 1.14.0
Oracle
From 8.0.0 to 8.1.0
From 8.2.0 to 8.2.3
From 8.2.0 to 8.2.4.0
Version 6.4
Version 7.3.6
From 8.0.0 to 8.2.4.0
From 8.0.0 to 8.2.4.0
Oracle
Version 7.4.1
Version 7.4.2
Version 7.5.0
From 12.6.0 to 12.6.4
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
From 8.0.8 to 8.1.1
Version 8.1.0
From 11.0 to 11.3.1
Oracle
Version 11.0.2
Version 11.1.0
Version 11.2.7
Version 11.3.0
Version 11.3.1
Up to 8.0.25
Version 16.0
From 16.0 to 19.0
Oracle
Version 14.1.3.2
Version 15.0.3.1
Version 16.0.3
Oracle
Version 14.1.3.2
Version 15.0.3.1
Version 16.0.3
Version 19.0.1
Version 16.0
Oracle
Version 14.1.3
Version 15.0.3
Version 16.0.3
Oracle
Version 6.0.0.1.1
Version 6.0.0.2.2
Version 6.0.0.3.1
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions

References (14)

Source: security@vmware.com
Third Party Advisory
Source: security@vmware.com
Third Party Advisory
Source: security@vmware.com
PatchThird Party Advisory
Source: security@vmware.com
PatchThird Party Advisory
Source: security@vmware.com
PatchThird Party Advisory
Source: security@vmware.com
PatchThird Party Advisory
Source: security@vmware.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.