VDB
CVE-2020-5413
CVE-2020-5413
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Code execution in Spring Integration
EPSS 4.41% · 90.4th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
4.41%
90.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| oracle | banking_credit_facilities_process_management | 14.2.0, 14.5.0, 14.3.0 |
| oracle | retail_customer_management_and_segmentation_foundation | 16.0 |
| Spring by VMware | Spring Integration | 5.2, 4.3, 5.1 |
| Maven | org.springframework.integration:spring-integration-core | 4.3.0, 5.3.0, 5.2.0 |
| oracle | retail_merchandising_system | 16.0.3 |
| oracle | banking_virtual_account_management | 14.2.0, 14.3.0, 14.5.0 |
| oracle | banking_corporate_lending_process_management | 14.5.0, 14.2.0, 14.3.0 |
| oracle | flexcube_private_banking | 12.1.0, 12.0.0 |
| vmware | spring_integration | 5.1.0, 5.3.0, 5.2.0 |
| oracle | banking_supply_chain_finance | 14.2.0, 14.3.0, 14.5.0 |
Timeline
- Jul 31, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://tanzu.vmware.com/security/cve-2020-5413 url
- https://www.oracle.com/security-alerts/cpuApr2021.html url
- https://www.oracle.com//security-alerts/cpujul2021.html url
- https://www.oracle.com/security-alerts/cpuoct2021.html url
- https://www.oracle.com/security-alerts/cpuapr2022.html url
- https://nvd.nist.gov/vuln/detail/CVE-2020-5413 advisory
- https://github.com/spring-projects/spring-integration/commit/6a02b5abe97fabab6003d51b98dd45ab009a6e05 url
- https://github.com/spring-projects/spring-integration package