|
|||
Rule General Information |
---|
Release Date: | 2014-01-02 | |
Rule Name: | VMware SpringSource Spring Framework class.classloader Remote Code Execution Vulnerability (CVE-2010-1622) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader followed by a URL of a crafted .jar file. | |
Impact: | Remote code execution | |
Affected OS: | Windows, Mac OS, Other Unix, Linux | |
Reference: | CVE-2010-1622 |
|
Solutions |
---|
Update vendor's patch. |