Permissions, Privileges, and Access Controls in Spring Framework and Spring Security - CVE-2016-5007

 

Permissions, Privileges, and Access Controls in Spring Framework and Spring Security - CVE-2016-5007

Published: October 27, 2023


Vulnerability identifier: #VU82532
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5007
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to both Spring Security and the Spring Framework rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. A remote attacker can trigger the vulnerability to bypass security restrictions.


Affected software

Spring Framework
Spring Security
openEuler
Storage Copy Data Management
IBM Engineering Requirements Management DOORS Next
springframework
springframework-help
springframework-context
springframework-expression
springframework-aop
springframework-web
springframework-tx
springframework-orm
springframework-beans
springframework-orm-hibernate4
springframework-jdbc
springframework-instrument
springframework-oxm
springframework-jms

How to mitigate CVE-2016-5007

Install updates from vendor's website.

Storage Copy Data Management - update to 2.2.26.0
springframework - update to 3.2.18-8
springframework-help - update to 3.2.18-8
springframework-context - update to 3.2.18-8
springframework-expression - update to 3.2.18-8
springframework-aop - update to 3.2.18-8
springframework-web - update to 3.2.18-8
springframework-tx - update to 3.2.18-8
springframework-orm - update to 3.2.18-8
springframework-beans - update to 3.2.18-8
springframework-orm-hibernate4 - update to 3.2.18-8
springframework-jdbc - update to 3.2.18-8
springframework-instrument - update to 3.2.18-8
springframework-oxm - update to 3.2.18-8
springframework-jms - update to 3.2.18-8
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7

External References

Related Security Bulletins