9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Affected (47)
Products: Vmware: Spring Cloud Function · Oracle: Banking Branch, Banking Cash Management, Banking Corporate Lending Process Management, Banking Credit Facilities Process Management, Banking Electronic Data Exchange For Corporates, Banking Liquidity Management, Banking Origination, Banking Supply Chain Finance, Banking Trade Finance Process Management, Banking Virtual Account Management, Communications Cloud Native Core Automated Test Suite, Communications Cloud Native Core Console, Communications Cloud Native Core Network Exposure Function, Communications Cloud Native Core Network Function Cloud Native Environment, Communications Cloud Native Core Network Repository Function, Communications Cloud Native Core Network Slice Selection Function, Communications Cloud Native Core Policy, Communications Cloud Native Core Security Edge Protection Proxy, Communications Cloud Native Core Unified Data Repository, Communications Communications Policy Management, Financial Services Analytical Applications Infrastructure, Financial Services Behavior Detection Platform, Financial Services Enterprise Case Management, Mysql Enterprise Monitor, Product Lifecycle Analytics, Retail Xstore Point Of Service, Sd Wan Edge
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.1.6 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.5 | |
| Version 14.5 | |
| Version 14.5 | |
| Version 14.5 | |
| Version 14.5 | |
| Version 14.2 | |
| Version 14.5 | |
| Version 14.5 | |
| Version 14.5 | |
| Version 14.5 | |
| Version 1.9.0 | |
| Version 1.9.0 | |
| Version 22.1.0 | |
| Version 1.10.0 | |
| Version 1.15.0 | |
| Version 1.8.0 | |
| Version 1.15.0 | |
| Version 1.7.0 | |
| Version 1.15.0 | |
| Version 12.6.0.0.0 | |
| Version 8.1.1.0 | |
| Version 8.1.1.0 | |
| Version 8.1.1.0 | |
| Up to 8.0.29 | |
| Version 3.6.1.0 | |
| Version 20.0.1 | |
| Version 9.0 |
Related CWEs
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.
CWE-94
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
References (13)
Source: security@vmware.com
ExploitThird Party AdvisoryVDB Entry
Source: security@vmware.com
Third Party Advisory
Source: security@vmware.com
Third Party Advisory
Source: security@vmware.com
PatchThird Party Advisory
Source: security@vmware.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.