Vulnerabilities > CVE-2015-5211 - Files or Directories Accessible to External Parties vulnerability in multiple products

047910
CVSS 9.6 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
vmware
debian
CWE-552
critical
nessus

Summary

Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.

Nessus

  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2015-693035254A.NASL
    descriptionSecurity fix for CVE-2015-5211. Update to 3.2.15.RELEASE Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2016-03-04
    plugin id89264
    published2016-03-04
    reporterThis script is Copyright (C) 2016-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/89264
    titleFedora 22 : springframework-3.2.15-1.fc22 (2015-693035254a)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2015-065D9953E8.NASL
    descriptionSecurity fix for CVE-2015-5211. Update to 3.2.15.RELEASE Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2016-03-04
    plugin id89133
    published2016-03-04
    reporterThis script is Copyright (C) 2016-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/89133
    titleFedora 23 : springframework-3.2.15-1.fc23 (2015-065d9953e8)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2015-9295D75400.NASL
    descriptionSecurity fix for CVE-2015-5211. Update to 3.2.15.RELEASE Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2016-03-04
    plugin id89326
    published2016-03-04
    reporterThis script is Copyright (C) 2016-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/89326
    titleFedora 21 : springframework-3.2.15-1.fc21 (2015-9295d75400)
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DLA-1853.NASL
    descriptionVulnerabilities have been identified in libspring-java, a modular Java/J2EE application framework. CVE-2014-3578 A directory traversal vulnerability that allows remote attackers to read arbitrary files via a crafted URL. CVE-2014-3625 A directory traversal vulnerability that allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling. CVE-2015-3192 Improper processing of inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file. CVE-2015-5211 Reflected File Download (RFD) attack vulnerability, which allows a malicious user to craft a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response. CVE-2016-9878 Improper path sanitization in ResourceServlet, which allows directory traversal attacks. For Debian 8
    last seen2020-06-01
    modified2020-06-02
    plugin id126653
    published2019-07-15
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/126653
    titleDebian DLA-1853-1 : libspring-java security update