CVE-2011-2730: High severity ibm security directory suite vulnerability
Spring Framework could allow a remote attacker to obtain sensitive information, caused by an error when handling the Expression Language. An attacker could exploit this vulnerability to obtain classpaths and other sensitive information.
Other sources
VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (EL), evaluates EL expressions in tags twice, which allows remote attackers to obtain sensitive information via a (1) name attribute in a (a) spring:hasBindErrors tag; (2) path attribute in a (b) spring:bind or (c) spring:nestedpath tag; (3) arguments, (4) code, (5) text, (6) var, (7) scope, or (8) message attribute in a (d) spring:message or (e) spring:theme tag; or (9) var, (10) scope, or (11) value attribute in a (f) spring:transform tag, aka "Expression Language Injection."
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2011-2730.
What is the severity of CVE-2011-2730?
The severity of CVE-2011-2730 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2011-2730?
The affected software versions are SpringSource Spring Framework 2.5.0, 3.0.1, 2.5.3, 3.0.2, 2.5.5, 2.5.6, and up to 2.5.7_sr01.
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by evaluating Expression Language (EL) expressions in tags twice.
Are there any references for CVE-2011-2730?
Yes, you can refer to the following links: [1](https://docs.google.com/document/d/1dc1xxO8UMFaGLOwgkykYdghGWm_2Gn0iCrxFsympqcE/edit), [2](http://www.debian.org/security/2012/dsa-2504), [3](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=677814).