← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-22112

Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the application's intent is to only allow the user to run with elevated privileges in a small portion of the application, the bug can be leveraged to extend those privileges to the rest of the application.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
EPSS Probability:3.17%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
pivotal_software spring_security all
vmware spring_security all
oracle communications_element_manager all
oracle communications_interactive_session_recorder 6.3, 6.4
oracle communications_unified_inventory_management 7.4.1
oracle hospitality_cruise_shipboard_property_management_system 20.1.0
oracle insurance_policy_administration 11.2.0, 11.3.0
oracle mysql_enterprise_monitor all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
3.171%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVMware by Broadcom · Vendor · USA
Reserved2021-01-04T00:00:00
Published2021-02-23T18:48:02
Last Updated2024-08-03T18:30:24

LINK COPIED TO CLIPBOARD