Known vulnerabilities in Spring Security - page 2
Vendor:
Broadcom
Software:
Spring Security
Software CPE:
cpe:2.3:a:broadcom:spring_security:*:*:*:*:*:*:*:*
Website:
https://www.broadcom.com/
Total vulnerabilities:
37
Public exploits:
3
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
6.3.16
5.8.25
5.7.23
6.4.16
6.4.15
6.3.15
5.8.24
6.4.14
6.3.14
6.3.13
6.3.12
6.3.11
5.8.23
5.8.22
5.8.21
5.8.20
5.7.22
5.7.21
5.7.20
5.7.19
5.7.18
7.0.4
6.5.9
7.0.3
6.5.8
7.0.2
7.0.1
7.0.0
6.5.7
6.4.13
6.5.6
6.4.12
6.5.5
6.4.11
6.5.4
6.4.10
6.5.3
6.4.9
6.5.2
6.4.8
6.5.1
6.4.7
6.3.10
6.5.0
6.4.6
5.7.17
5.8.19
6.0.17
6.1.15
6.2.11
6.4.5
6.3.9
5.7.16
5.8.18
6.0.16
6.1.14
6.2.10
5.7.15
5.8.17
6.0.15
6.1.13
6.2.9
6.4.4
6.3.8
6.4.3
6.3.7
6.4.2
6.3.6
6.4.1
6.1.12
6.0.14
6.4.0
6.3.5
6.2.8
5.8.16
5.7.14
6.1.11
6.1.10
6.0.13
6.0.12
6.0.11
6.3.4
6.2.7
5.8.15
5.7.13
6.3.3
6.3.2
6.2.6
5.8.14
6.3.1
6.2.5
5.8.13
6.3.0
6.2.4
6.1.9
5.8.12
6.0.10
6.0.9
6.2.3
6.1.8
5.8.11
5.7.12
6.2.2
6.1.7
5.8.10
5.8.9
6.2.1
6.1.6
6.2.0
6.1.5
6.0.8
5.8.8
6.1.4
6.0.7
5.8.7
5.7.11
6.1.3
6.0.6
5.8.6
6.1.2
6.0.5
5.8.5
5.7.10
5.6.12
6.1.1
6.0.4
5.8.4
5.7.9
5.6.11
6.1.0
6.0.3
5.8.3
5.7.8
5.4.11
5.7.7
6.0.2
5.8.2
6.0.1
5.8.1
5.7.6
5.6.10
6.0.0
5.8.0
5.7.5
5.6.9
5.7.4
5.6.8
5.7.3
5.6.7
5.7.2
5.6.6
5.7.1
5.6.5
5.5.8
5.5.0-M1
5.4.0-M1
5.7.0
5.6.4
5.5.7
5.6.3
5.5.6
5.6.2
5.5.5
5.6.1
5.4.10
5.5.4
5.6.0
5.5.3
5.4.9
5.4.8
5.5.2
5.4.7
5.5.1
5.4.6
5.3.7
5.2.9
5.3.8
5.4.5
5.4.3
5.4.4
4.2.20
5.4.2
5.3.6
5.2.8
5.5.0
5.4.1
5.3.5
4.2.19
5.0.19
5.1.13
5.2.7
5.1.12
5.3.4
5.0.18
5.2.6
4.2.18
5.4.0-M2
5.0.17
5.1.11
5.2.5
5.3.3
4.2.17
5.4.0
5.3.2
5.3.1
5.3.0
5.2.4
5.2.3
5.2.2
5.2.1
5.2.0
5.1.10
5.1.9
5.1.8
5.1.7
5.1.6
5.1.5
5.1.4
5.1.3
5.1.2
5.1.1
5.1.0
5.0.16
5.0.15
5.0.14
5.0.13
5.0.12
5.0.11
5.0.10
5.0.9
5.0.8
5.0.7
5.0.6
5.0.5
5.0.4
5.0.3
5.0.2
5.0.1
5.0.0
4.2.16
4.2.15
4.2.14
4.2.13
4.2.12
4.2.11
4.2.10
4.2.9
4.2.7
4.2.6
4.2.5
4.2.4
4.2.3
4.2.2
4.2.1
4.2.0
4.1.5
4.1.4
4.1.3
4.1.2
4.1.1
4.1.0
4.0.4
4.0.3
4.0.2
4.0.1
4.0.0
3.2.10
3.2.9
3.2.8
3.2.7
3.2.6
3.2.5
3.2.4
3.2.3
3.2.2
3.2.1
3.2.0
3.1.7
3.1.6
3.1.5
3.1.4
3.1.3
3.1.2
3.1.1
3.1.0
3.0.8
3.0.7
3.0.6
3.0.5
3.0.4
3.0.3
3.0.2
3.0.1
3.0.0
2.5.0
2.0.8
2.0.7
2.0.6
2.0.5
2.0.4
2.0.3
2.0.2
2.0.1
2.0.0
1.0.7
1.0.6
1.0.5
1.0.4
1.0.3
1.0.2
1.0.1
1.0.0
7.1.1
7.0.7
7.1.0
7.0.6
6.5.11
7.0.5
6.5.10
Vulnerabilities (37)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU82227 - Incorrect Authorization CVE-2023-34035 |
CWE-863 | Medium | 5.8.5, 6.0.5, 6.1.2 | 18.10.2023 |
SB2023071828 SB2023122252 SB2023122810 and 3 more |
||
| #VU80880 - Security Features CVE-2023-34034 |
CWE-254 | High | 5.6.12, 5.7.10, 5.8.5, 6.0.5, 6.1.2 | 19.09.2023 |
SB2023091914 SB2023100926 SB20231017104 and 22 more |
||
| #VU75408 - Security Features CVE-2023-20862 |
CWE-254 | Medium | 5.7.8, 5.8.3, 6.0.3 | 21.04.2023 |
SB2023042130 SB2023042132 SB2023053121 and 20 more |
||
| #VU75044 - Uncontrolled Recursion CVE-2023-1370 |
CWE-674 | Medium | 5.8.4 | 12.04.2023 |
SB2023041258 SB2023041259 SB2023041809 and 130 more |
||
| #VU68866 - Improper Authorization CVE-2022-31692 |
CWE-285 | High | 5.6.9, 5.7.5 | 01.11.2022 |
SB2022110101 SB2022121119 SB2023011162 and 28 more |
||
| #VU68865 - Permissions, Privileges, and Access Controls CVE-2022-31690 |
CWE-264 | Medium | 5.6.9, 5.7.5 | 01.11.2022 |
SB2022110101 SB2022121119 SB2023012108 and 9 more |
||
| #VU63345 - Improper Authorization CVE-2022-22978 |
CWE-285 | High | 5.5.7, 5.6.4 | 17.05.2022 |
SB2022051717 SB2022052009 SB2022052010 and 20 more |
||
| #VU63342 - Integer overflow CVE-2022-22976 |
CWE-190 | Low | 5.5.7, 5.6.4 | 17.05.2022 |
SB2022051717 SB2022052009 SB2022052010 and 7 more |
||
| #VU63301 - Improper Authorization CVE-2022-22975 |
CWE-285 | High | 5.5.7, 5.6.4 | 17.05.2022 |
SB2022051717 |
||
| #VU50820 - Permissions, Privileges, and Access Controls CVE-2021-22112 |
CWE-264 | Medium | 5.2.9, 5.3.8, 5.4.4 | 22.02.2021 |
SB2021022207 SB2021022216 SB2021042314 and 8 more |
||
| #VU28464 - Improper Verification of Cryptographic Signature CVE-2020-5407 |
CWE-347 | Medium | 5.2.4, 5.3.2 | 01.06.2020 |
SB2020060107 |
||
| #VU28463 - Use of Insufficiently Random Values CVE-2020-5408 |
CWE-330 | Medium | 4.2.16, 5.0.16, 5.1.10, 5.2.4, 5.3.2 | 01.06.2020 |
SB2020060107 SB2020102832 SB2020102833 and 13 more |
||
| #VU24168 - Improper input validation CVE-2019-17195 |
CWE-20 | Medium | 5.2.2, 5.3.0 | 09.01.2020 |
SB2019101519 SB2020010921 SB2020040218 and 20 more |
||
| #VU18957 - Credentials Management CVE-2019-11272 |
CWE-255 | Low | 4.2.13 | 02.07.2019 |
SB2019070206 SB2020032701 SB2023062703 and 1 more |
||
| #VU37874 - Deserialization of Untrusted Data CVE-2017-4995 |
CWE-502 | High | - | 27.11.2017 |
SB2017112718 |
||
| #VU38943 - Improper Authentication CVE-2014-0097 |
CWE-287 | Medium | - | 25.05.2017 |
SB2017052518 |
||
| #VU38944 - Improper Authentication CVE-2014-3527 |
CWE-287 | High | - | 25.05.2017 |
SB2017052519 |
Showing elements 21 - 40 out of 37