CVE-2010-1622
medium
CVSS v3
—
CVSS v2
6.0
VIR risk
6.0
Description
Improper Control of Generation of Code ('Code Injection') in Spring Framework
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://www.springsource.com/security/cve-2010-1622
Vendor advisory: secalert@redhat.com — http://geronimo.apache.org/22x-security-report.html
Vendor advisory: secalert@redhat.com — http://geronimo.apache.org/21x-security-report.html
Vendor advisory: secalert@redhat.com — http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.html
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.springframework:spring | >=2.5.0,<2.5.7 | 2.5.7 |
| Maven | org.springframework:spring | >=3.0.0,<3.0.3 | 3.0.3 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| oracle | fusion_middleware | 7.6.2 | |
| oracle | fusion_middleware | 11.1.1.6.1 | |
| oracle | fusion_middleware | 11.1.1.8.0 | |
| springsource | spring_framework | 2.5.0 | |
| springsource | spring_framework | 2.5.1 | |
| springsource | spring_framework | 2.5.2 | |
| springsource | spring_framework | 2.5.3 | |
| springsource | spring_framework | 2.5.4 | |
| springsource | spring_framework | 2.5.5 | |
| springsource | spring_framework | 2.5.6 | |
| springsource | spring_framework | 2.5.7 | |
| springsource | spring_framework | 3.0.0 | |
| springsource | spring_framework | 3.0.1 | |
| springsource | spring_framework | 3.0.2 | |
References
- http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.html
- http://geronimo.apache.org/21x-security-report.html
- http://geronimo.apache.org/22x-security-report.html
- http://secunia.com/advisories/41016
- http://secunia.com/advisories/41025
- http://secunia.com/advisories/43087
- http://www.exploit-db.com/exploits/13918
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- http://www.redhat.com/support/errata/RHSA-2011-0175.html
- http://www.securityfocus.com/archive/1/511877
- http://www.securityfocus.com/bid/40954
- http://www.securitytracker.com/id/1033898
- http://www.springsource.com/security/cve-2010-1622
- http://www.vupen.com/english/advisories/2011/0237
- https://nvd.nist.gov/vuln/detail/CVE-2010-1622
- https://github.com/spring-projects/spring-framework/commit/3a5af35d37c79d0644d49b93f792a4c18fe8eb71
- https://access.redhat.com/errata/RHSA-2011:0175
- https://access.redhat.com/security/cve/CVE-2010-1622
- https://bugzilla.redhat.com/show_bug.cgi?id=606706
- https://github.com/spring-projects/spring-framework
- https://seclists.org/fulldisclosure/2010/Jun/456
- https://web.archive.org/web/20100623011648/http://www.springsource.com/security/cve-2010-1622
- https://web.archive.org/web/20161014113129/http://www.securitytracker.com/id/1033898
- https://web.archive.org/web/20200227210033/http://www.securityfocus.com/archive/1/511877
- https://web.archive.org/web/20200228060816/http://www.securityfocus.com/bid/40954
CWEs
CWE-94
Verify integrity in audit chain (admin only). AS-IS.