← Back

CVE-2026-47842

nvd nist
Published: Aug 26, 2026Modified: Sep 4, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: security@vmware.com (Secondary)

Description

Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using a null (all-zero) initialization vector. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25

Affected (6)

1 product
Spring Security
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
From 5.7.0 to 5.7.26
From 5.8.0 to 5.8.28
From 6.4.0 to 6.4.19
From 6.5.0 to 6.5.12
From 7.0.0 to 7.0.6.1
From 7.1.0 to 7.1.0.1

References (1)

Source: security@vmware.com
Vendor Advisory

Timeline

No history available yet.