Configuration in Spring Framework - CVE-2011-2730

 

Configuration in Spring Framework - CVE-2011-2730

Published: April 24, 2024


Vulnerability identifier: #VU88954
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-2730
CWE-ID: CWE-16
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The issue may allow a local user to bypass implemented security restrictions.

The issue exists due to the possibility to bypass implemented security restrictions, related to secure boot. it was addressed by rebuilding the package with the new secure boot key.


Affected software

Spring Framework
MobileFirst Platform

How to mitigate CVE-2011-2730

Install updates from vendor's website.

Spring Framework - addressed in versions 2.5.6.SEC03, 2.5.7.SR023, 3.0.6
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031

External References

Related Security Bulletins