Use of insufficiently random values in Spring Security - CVE-2020-5408

 

Use of insufficiently random values in Spring Security - CVE-2020-5408

Published: June 1, 2020


Vulnerability identifier: #VU28463
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-5408
CWE-ID: CWE-330
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the affected software uses a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A remote authenticated attacker can derive the unencrypted values using a dictionary attack.


Affected software

Spring Security
Dell Support Assist Enterprise
Oracle FLEXCUBE Private Banking
CloudLink
MySQL Enterprise Monitor
Oracle Communications Element Manager
Oracle Communications Session Route Manager
Oracle Banking Liquidity Management
Oracle Banking Trade Finance Process Management
Oracle Banking Corporate Lending Process Management
Oracle Banking Credit Facilities Process Management
Oracle Banking Virtual Account Management
Oracle Banking Supply Chain Finance
Oracle Communications Session Report Manager
IBM Sterling Connect:Direct Web Services
IBM Cognos Controller

How to mitigate CVE-2020-5408

Install updates from vendor's website.

Spring Security - addressed in versions 4.2.16, 5.0.16, 5.1.10, 5.2.4, 5.3.2
Dell Support Assist Enterprise - update to 4.00.06.00
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.24, 6.2.0.23, 6.3.0.7
CloudLink - update to 8.0-3.10.5.1
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2

External References

Related Security Bulletins