CVE-2010-3700: Medium severity Acegisecurity Acegi-security vulnerability
VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3700?
CVE-2010-3700 has been classified with a high severity rating due to the risk of unauthorized access.
How do I fix CVE-2010-3700?
To fix CVE-2010-3700, update to Spring Security versions 2.0.6 or 3.0.4 or later, or Acegi Security version 1.0.8.
Who is affected by CVE-2010-3700?
CVE-2010-3700 affects users of Acegi Security versions 1.0.0 through 1.0.7 and VMware Spring Security versions 2.x before 2.0.6 and 3.x before 3.0.4.
What kind of attack can exploit CVE-2010-3700?
CVE-2010-3700 can be exploited by remote attackers to bypass security constraints via manipulated path parameters.
Is CVE-2010-3700 still relevant today?
While CVE-2010-3700 is an older vulnerability, it remains relevant for systems still using affected versions of the software.