Vulnerabilities > Vmware > Spring Integration ZIP > 1.0.0

DATE CVE VULNERABILITY TITLE RISK
2018-05-15 CVE-2018-1263 Path Traversal vulnerability in VMWare Spring Integration ZIP 1.0.0/1.0.1
Addresses partial fix in CVE-2018-1261.
network
high complexity
vmware CWE-22
4.0
2018-05-11 CVE-2018-1261 Path Traversal vulnerability in VMWare Spring Integration ZIP 1.0.0
Spring-integration-zip versions prior to 1.0.1 exposes an arbitrary file write vulnerability, which can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z) that holds path traversal filenames.
network
high complexity
vmware CWE-22
4.0