In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "8.0.0"
},
{
"last_affected": "8.2.2"
}
],
"vendor_product": "oracle:communications_diameter_signaling_router",
"cpes": [
"cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE"
},
{
"extracted_events": [
{
"introduced": "11.0.0"
},
{
"last_affected": "11.3.1"
}
],
"cpes": [
"cpe:2.3:a:oracle:insurance_calculation_engine:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE",
"vendor_product": "oracle:insurance_calculation_engine"
},
{
"extracted_events": [
{
"last_affected": "2.1.1"
}
],
"source": "CPE_RANGE",
"vendor_product": "oracle:siebel_engineering_-_installer_&_deployment",
"cpes": [
"cpe:2.3:a:oracle:siebel_engineering_-_installer_\\&_deployment:*:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "13.3.0.1"
}
],
"cpes": [
"cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "oracle:application_testing_suite"
},
{
"extracted_events": [
{
"last_affected": "11.3"
},
{
"last_affected": "12.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_billing_and_revenue_management_elastic_charging_engine:11.3:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_billing_and_revenue_management_elastic_charging_engine:12.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "oracle:communications_billing_and_revenue_management_elastic_charging_engine"
},
{
"extracted_events": [
{
"last_affected": "1.5.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.5.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "oracle:communications_cloud_native_core_policy"
},
{
"extracted_events": [
{
"last_affected": "8.1.1"
},
{
"last_affected": "8.2.0"
},
{
"last_affected": "8.2.1"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_element_manager:8.2.1:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "oracle:communications_element_manager"
},
{
"extracted_events": [
{
"last_affected": "12.5.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_policy_management:12.5.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "oracle:communications_policy_management"
},
{
"extracted_events": [
{
"last_affected": "8.1.1"
},
{
"last_affected": "8.2.0"
},
{
"last_affected": "8.2.1"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:communications_session_report_manager",
"cpes": [
"cpe:2.3:a:oracle:communications_session_report_manager:8.1.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_session_report_manager:8.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_session_report_manager:8.2.1:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "8.1.1"
},
{
"last_affected": "8.2.0"
},
{
"last_affected": "8.2.1"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_session_route_manager:8.1.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_session_route_manager:8.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_session_route_manager:8.2.1:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "oracle:communications_session_route_manager"
},
{
"extracted_events": [
{
"last_affected": "13.2.1.0"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:enterprise_manager_base_platform",
"cpes": [
"cpe:2.3:a:oracle:enterprise_manager_base_platform:13.2.1.0:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "8.0.9.2.0"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:financial_services_regulatory_reporting_with_agilereporter",
"cpes": [
"cpe:2.3:a:oracle:financial_services_regulatory_reporting_with_agilereporter:8.0.9.2.0:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "12.0.0"
},
{
"last_affected": "12.1.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "oracle:flexcube_private_banking"
},
{
"extracted_events": [
{
"last_affected": "4.0.2"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:healthcare_master_person_index",
"cpes": [
"cpe:2.3:a:oracle:healthcare_master_person_index:4.0.2:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "10.2.0"
},
{
"last_affected": "10.2.4"
},
{
"last_affected": "11.0.2"
},
{
"last_affected": "11.1.0"
},
{
"last_affected": "11.2.0"
},
{
"last_affected": "11.2.2.0"
}
],
"vendor_product": "oracle:insurance_policy_administration_j2ee",
"cpes": [
"cpe:2.3:a:oracle:insurance_policy_administration_j2ee:10.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_policy_administration_j2ee:10.2.4:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.1.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.2.2.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "10.2.0"
},
{
"last_affected": "10.2.4"
},
{
"last_affected": "11.0.2"
},
{
"last_affected": "11.1.0"
},
{
"last_affected": "11.2.0"
}
],
"vendor_product": "oracle:insurance_rules_palette",
"cpes": [
"cpe:2.3:a:oracle:insurance_rules_palette:10.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_rules_palette:10.2.4:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_rules_palette:11.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_rules_palette:11.1.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_rules_palette:11.2.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "12.1"
},
{
"last_affected": "12.2"
}
],
"cpes": [
"cpe:2.3:a:oracle:rapid_planning:12.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:rapid_planning:12.2:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "oracle:rapid_planning"
},
{
"extracted_events": [
{
"last_affected": "15.0"
},
{
"last_affected": "16.0"
}
],
"vendor_product": "oracle:retail_assortment_planning",
"cpes": [
"cpe:2.3:a:oracle:retail_assortment_planning:15.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_assortment_planning:16.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "14.1"
}
],
"vendor_product": "oracle:retail_back_office",
"cpes": [
"cpe:2.3:a:oracle:retail_back_office:14.1:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "16.0.3.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:retail_bulk_data_integration:16.0.3.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "oracle:retail_bulk_data_integration"
},
{
"extracted_events": [
{
"last_affected": "14.1"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:retail_central_office",
"cpes": [
"cpe:2.3:a:oracle:retail_central_office:14.1:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "15.0"
},
{
"last_affected": "16.0"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:retail_financial_integration",
"cpes": [
"cpe:2.3:a:oracle:retail_financial_integration:15.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_financial_integration:16.0:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "15.0.3"
},
{
"last_affected": "16.0.3"
}
],
"cpes": [
"cpe:2.3:a:oracle:retail_integration_bus:15.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_integration_bus:16.0.3:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "oracle:retail_integration_bus"
},
{
"extracted_events": [
{
"last_affected": "15.0"
},
{
"last_affected": "16.0"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:retail_order_broker",
"cpes": [
"cpe:2.3:a:oracle:retail_order_broker:15.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_order_broker:16.0:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "14.1"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:retail_point-of-service",
"cpes": [
"cpe:2.3:a:oracle:retail_point-of-service:14.1:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "14.0.3"
},
{
"last_affected": "14.1.3.0"
},
{
"last_affected": "15.0.3"
},
{
"last_affected": "16.0.3.0"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:retail_predictive_application_server",
"cpes": [
"cpe:2.3:a:oracle:retail_predictive_application_server:14.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_predictive_application_server:14.1.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_predictive_application_server:15.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_predictive_application_server:16.0.3.0:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "14.1"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:retail_returns_management",
"cpes": [
"cpe:2.3:a:oracle:retail_returns_management:14.1:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "15.0"
},
{
"last_affected": "16.0"
}
],
"vendor_product": "oracle:retail_service_backbone",
"cpes": [
"cpe:2.3:a:oracle:retail_service_backbone:15.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_service_backbone:16.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "12.2.1.3.0"
},
{
"last_affected": "12.2.1.4.0"
}
],
"vendor_product": "oracle:weblogic_server",
"cpes": [
"cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING"
}
]
}{
"cpe": "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "4.0.0"
},
{
"last_affected": "4.0.12"
},
{
"introduced": "8.0.0"
},
{
"last_affected": "8.0.20"
}
],
"source": "CPE_RANGE"
}{
"cpe": "cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "5.0.0"
},
{
"fixed": "5.0.16"
},
{
"introduced": "5.1.0"
},
{
"fixed": "5.1.13"
},
{
"introduced": "5.2.0"
},
{
"fixed": "5.2.3"
}
],
"source": "CPE_RANGE"
}