Path traversal in Spring Framework - CVE-2024-38819

 

Path traversal in Spring Framework - CVE-2024-38819

Published: October 17, 2024 / Updated: December 19, 2024


Vulnerability identifier: #VU98796
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38819
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in applications that serve static resources through the functional web frameworks WebMvc.fn or WebFlux.fn. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.


Affected software

Spring Framework
IBM Cloud Pak for Security
Enterprise Project Connection
Jira Service Management Data Center
Jira Service Management Server
IBM Spectrum Symphony
Confluence Data Center
Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition
Oracle Financial Services Behavior Detection Platform
Oracle Financial Services Model Management and Governance
Oracle Healthcare Data Repository
Bitbucket Data Center
Oracle SD-WAN Edge
Jira Software Data Center
Oracle Middleware Common Libraries and Tools
IBM Cloud Pak for Business Automation
Oracle Communications Cloud Native Core Network Data Analytics Function
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Binding Support Function
IBM Observability with Instana
IBM Process Mining
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Dell Secure Connect Gateway
QRadar Suite
Cloudera Observability with IBM
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Knowledge Catalog Premium Cartridge
Oracle Healthcare Master Person Index
DevOps Solution Workbench
IBM Tivoli Netcool Configuration Manager
Oracle Financial Services Analytical Applications Infrastructure
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
Telco Service Design Configuration Designer
Telco Network Function Virtualization Orchestrator
Oracle Solaris Cluster
Communications Unified Assurance
Oracle Utilities Testing Accelerator
Oracle Financial Services Compliance Studio
Oracle Communications Element Manager
Confluence Server
Bitbucket Server
Oracle WebLogic Server
Oracle Retail Predictive Application Server
Jira Software Server
Oracle Commerce Guided Search
Oracle Retail Financial Integration
SAP Commerce Cloud
Identity Manager
Oracle Documaker
Operational Decision Manager
Oracle Enterprise Manager for Fusion Middleware
Enterprise Manager for MySQL Database
Primavera Unifier
Oracle Retail Integration Bus
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Unified Data Repository
SAP Datahub
Library Support for Spring
Red Hat Camel for Spring Boot
IBM InfoSphere Information Server

How to mitigate CVE-2024-38819

Install update from vendor's website.

Spring Framework - addressed in versions 5.3.41, 6.0.25, 6.1.14
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
Cloudera Observability with IBM - update to 3.6.2
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
Knowledge Catalog Premium Cartridge - update to 5.2
Jira Service Management Data Center - update to 5.12.19
Jira Service Management Server - update to 5.12.19
Oracle Utilities Testing Accelerator - update to 6.0.0.3.1
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.22
IBM Spectrum Symphony - update to 7.3.2 FP3
Confluence Data Center - addressed in versions 7.19.30, 8.5.18, 9.1.1
Confluence Server - addressed in versions 7.19.30, 8.5.18, 9.1.1
Bitbucket Server - addressed in versions 8.9.24, 8.19.13, 8.19.25
Bitbucket Data Center - update to 8.19.25
Jira Software Data Center - update to 9.12.18
Jira Software Server - update to 9.12.18
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
IBM Observability with Instana - update to 286
IBM Process Mining - update to 1.15.0 IF004
Telco Service Design Configuration Designer - update to 2.3.0
Library Support for Spring - update to 2.7.29
Red Hat Camel for Spring Boot - update to 4.8
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.1.1
Dell Secure Connect Gateway - update to 5.28.00.14
Telco Network Function Virtualization Orchestrator - update to 7.3.0
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 49, 8.11.1 Interim fix 47, 8.12.0.1 Interim fix 31, 9.0.0.1 Interim fix 15, 9.5.0.0 Interim fix 7
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins