First published: Thu Dec 22 2016(Updated: )
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
Credit: security_alert@emc.com security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pivotal Software Spring Framework | <=3.2.0 | |
Pivotal Software Spring Framework | =4.2.0 | |
Pivotal Software Spring Framework | =4.3.0 | |
VMware Spring Framework | =3.2.1 | |
VMware Spring Framework | =3.2.2 | |
VMware Spring Framework | =3.2.3 | |
VMware Spring Framework | =3.2.4 | |
VMware Spring Framework | =3.2.5 | |
VMware Spring Framework | =3.2.6 | |
VMware Spring Framework | =3.2.7 | |
VMware Spring Framework | =3.2.8 | |
VMware Spring Framework | =3.2.9 | |
VMware Spring Framework | =3.2.10 | |
VMware Spring Framework | =3.2.11 | |
VMware Spring Framework | =3.2.12 | |
VMware Spring Framework | =3.2.13 | |
VMware Spring Framework | =3.2.14 | |
VMware Spring Framework | =3.2.15 | |
VMware Spring Framework | =3.2.16 | |
VMware Spring Framework | =3.2.17 | |
VMware Spring Framework | =4.2.1 | |
VMware Spring Framework | =4.2.2 | |
VMware Spring Framework | =4.2.3 | |
VMware Spring Framework | =4.2.4 | |
VMware Spring Framework | =4.2.5 | |
VMware Spring Framework | =4.2.6 | |
VMware Spring Framework | =4.2.7 | |
VMware Spring Framework | =4.2.8 | |
VMware Spring Framework | =4.3.1 | |
VMware Spring Framework | =4.3.2 | |
VMware Spring Framework | =4.3.3 | |
VMware Spring Framework | =4.3.4 | |
redhat/Spring Framework | <3.2.18 | 3.2.18 |
redhat/Spring Framework | <4.2.9 | 4.2.9 |
redhat/Spring Framework | <4.3.5 | 4.3.5 |
maven/org.springframework:spring-webmvc | >=4.3.0<4.3.5 | 4.3.5 |
maven/org.springframework:spring-webmvc | >=4.2.0<4.2.9 | 4.2.9 |
maven/org.springframework:spring-webmvc | <3.2.18 | 3.2.18 |
IBM GDE | <=3.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue in Pivotal Spring Framework is CVE-2016-9878.
The severity of CVE-2016-9878 is high with a CVSS score of 7.5.
CVE-2016-9878 allows a remote attacker to traverse directories on the system and view arbitrary files.
Versions 3.2.0 to 3.2.18, 4.2.0 to 4.2.9, and 4.3.0 to 4.3.5 of Pivotal Spring Framework are affected by CVE-2016-9878.
To fix CVE-2016-9878, update Pivotal Spring Framework to version 3.2.18, 4.2.9, or 4.3.5.