CVE-2010-1622: Code Injection
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1622 to the following vulnerability:
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.
References: [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1622 [2] http://www.securityfocus.com/archive/1/511877 [3] http://www.exploit-db.com/exploits/13918 [4] http://www.springsource.com/security/cve-2010-1622 [5] http://www.securityfocus.com/bid/40954
Credit: The issue was discovered by Meder Kydyraliev, Google Security Team
Other sources
Spring Framework could allow a remote attacker to execute arbitrary code on the system, caused by an error in the mechanism to use client provided data to update the properties of an object. An attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is CVE-2010-1622?
CVE-2010-1622 is a vulnerability in the Spring Framework that allows a remote attacker to execute arbitrary code on the system.
How does CVE-2010-1622 occur?
CVE-2010-1622 occurs due to an error in the mechanism to use client provided data to update the properties of an object.
What is the severity of CVE-2010-1622?
The severity of CVE-2010-1622 is high, with a severity value of 7.5.
Which software versions are affected by CVE-2010-1622?
Oracle Fusion Middleware versions 11.1.1.8.0, 7.6.2, and 11.1.1.6.1, as well as SpringSource Spring Framework versions 2.5.x, 3.0.x are affected by CVE-2010-1622.
How can I fix CVE-2010-1622?
To fix CVE-2010-1622, update to Spring Framework versions 2.5.6.SEC02, 2.5.7.SR01, or 3.0.2 or apply the necessary patches provided by the vendor.