Files or Directories Accessible to External Parties in Spring Framework - CVE-2015-5211

 

Files or Directories Accessible to External Parties in Spring Framework - CVE-2015-5211

Published: June 8, 2023


Vulnerability identifier: #VU77101
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-5211
CWE-ID: CWE-552
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to Reflected File Download (RFD) attack. A remote unauthenticated attacker can perform a Reflected File Download (RFD) attack by tricking victim into opening a specially crafted URL with a batch script extension and then execute arbitrary code on the target system.


Affected software

Spring Framework
watsonx.data
Fedora
Storage Copy Data Management
IBM Tivoli Netcool Configuration Manager
springframework

How to mitigate CVE-2015-5211

Install updates from vendor's website.

Spring Framework - addressed in versions 3.2.15, 4.1.8, 4.2.2
watsonx.data - update to 2.1
Storage Copy Data Management - update to 2.2.26.0
springframework - addressed in versions 3.2.15-1.fc21, 3.2.15-1.fc22, 3.2.15-1.fc23
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.18

External References

Related Security Bulletins