PT-2020-2651 · Oracle+2 · Oracle Retail Order Broker+2

Published

2020-01-16

·

Updated

2025-09-29

·

CVE-2020-5398

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Spring Framework versions 5.0.x prior to 5.0.16 Spring Framework versions 5.1.x prior to 5.1.13 Spring Framework versions 5.2.x prior to 5.2.3 Oracle Retail Order Broker (affected versions not specified)
Description The issue exists due to inadequate protection of the web page structure in the Spring Framework component of Oracle Retail Order Broker. This allows a remote attacker to gain full control over the application via the HTTP protocol. The vulnerability can be exploited through a reflected file download (RFD) attack when the application sets a "Content-Disposition" header in the response where the filename attribute is derived from user-supplied input.
Recommendations For Spring Framework versions 5.0.x prior to 5.0.16, update to version 5.0.16 or later. For Spring Framework versions 5.1.x prior to 5.1.13, update to version 5.1.13 or later. For Spring Framework versions 5.2.x prior to 5.2.3, update to version 5.2.3 or later. For Oracle Retail Order Broker, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_11035
ALSA-2025_16880
ALT-PU-2020-2640
ALT-PU-2021-2380
ALT-PU-2021-3668
BDU:2020-02695
CVE-2020-5398
GHSA-8WX2-9Q48-VM9R

Affected Products

Alt Linux
Oracle Retail Order Broker
Spring Framework