5
CVSSv2

CVE-2016-9878

Published: 29/12/2016 Updated: 11/04/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in Pivotal Spring Framework prior to 3.2.18, 4.2.x prior to 4.2.9, and 4.3.x prior to 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware spring framework 4.3.1

pivotal software spring framework 4.3.0

vmware spring framework 4.2.8

vmware spring framework 4.2.1

pivotal software spring framework 4.2.0

vmware spring framework 3.2.11

vmware spring framework 3.2.10

vmware spring framework 3.2.2

vmware spring framework 3.2.1

vmware spring framework 4.2.7

vmware spring framework 4.2.6

vmware spring framework 3.2.17

vmware spring framework 3.2.16

vmware spring framework 3.2.9

vmware spring framework 3.2.8

pivotal software spring framework

vmware spring framework 4.3.4

vmware spring framework 4.2.5

vmware spring framework 4.2.4

vmware spring framework 3.2.15

vmware spring framework 3.2.14

vmware spring framework 3.2.7

vmware spring framework 3.2.6

vmware spring framework 4.3.3

vmware spring framework 4.3.2

vmware spring framework 4.2.3

vmware spring framework 4.2.2

vmware spring framework 3.2.13

vmware spring framework 3.2.12

vmware spring framework 3.2.5

vmware spring framework 3.2.4

vmware spring framework 3.2.3

Vendor Advisories

Synopsis Moderate: Red Hat JBoss Fuse/A-MQ 63 R5 security and bug fix update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Fuse and Red Hat JBoss A-MQRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabilit ...
Debian Bug report logs - #849167 libspring-java: CVE-2016-9878 Package: src:libspring-java; Maintainer for src:libspring-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 23 Dec 2016 06:21:01 UTC Severity: important Tags: p ...
Multiple vulnerabilities have been found in Hitachi Infrastructure Analytics Advisor Affected products and versions are listed below Please upgrade your version to the appropriate version ...