{"id":"CVE-2020-5398","title":"In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a \"Content-Disposition\" header in…","summary":"In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a \"Content-Disposition\" header in…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-79","CWE-494"],"vendor":"vmware","product":"spring_framework","affected":["spring_framework >= 5.0.0, < 5.0.16","spring_framework >= 5.1.0, < 5.1.13","spring_framework >= 5.2.0, < 5.2.3","application_testing_suite = 13.3.0.1","communications_billing_and_revenue_management_elastic_charging_engine = 11.3","communications_billing_and_revenue_management_elastic_charging_engine = 12.0","communications_cloud_native_core_policy = 1.5.0","communications_diameter_signaling_router >= 8.0.0, <= 8.2.2","communications_element_manager = 8.1.1","communications_element_manager = 8.2.0","communications_element_manager = 8.2.1","communications_policy_management = 12.5.0","communications_session_report_manager = 8.1.1","communications_session_report_manager = 8.2.0","communications_session_report_manager = 8.2.1","communications_session_route_manager = 8.1.1","communications_session_route_manager = 8.2.0","communications_session_route_manager = 8.2.1","enterprise_manager_base_platform = 13.2.1.0","financial_services_regulatory_reporting_with_agilereporter = 8.0.9.2.0","flexcube_private_banking = 12.0.0","flexcube_private_banking = 12.1.0","healthcare_master_person_index = 4.0.2","insurance_calculation_engine >= 11.0.0, <= 11.3.1","insurance_policy_administration_j2ee = 10.2.0","insurance_policy_administration_j2ee = 10.2.4","insurance_policy_administration_j2ee = 11.0.2","insurance_policy_administration_j2ee = 11.1.0","insurance_policy_administration_j2ee = 11.2.0","insurance_policy_administration_j2ee = 11.2.2.0","insurance_rules_palette = 10.2.0","insurance_rules_palette = 10.2.4","insurance_rules_palette = 11.0.2","insurance_rules_palette = 11.1.0","insurance_rules_palette = 11.2.0","mysql >= 4.0.0, <= 4.0.12","mysql >= 8.0.0, <= 8.0.20","rapid_planning = 12.1","rapid_planning = 12.2","retail_assortment_planning = 15.0","retail_assortment_planning = 16.0","retail_back_office = 14.1","retail_bulk_data_integration = 16.0.3.0","retail_central_office = 14.1","retail_financial_integration = 15.0","retail_financial_integration = 16.0","retail_integration_bus = 15.0.3","retail_integration_bus = 16.0.3","retail_order_broker = 15.0","retail_order_broker = 16.0","retail_point-of-service = 14.1","retail_predictive_application_server = 14.0.3","retail_predictive_application_server = 14.1.3.0","retail_predictive_application_server = 15.0.3","retail_predictive_application_server = 16.0.3.0","retail_returns_management = 14.1","retail_service_backbone = 15.0","retail_service_backbone = 16.0","siebel_engineering_-_installer_&_deployment <= 2.1.1","weblogic_server = 12.2.1.3.0","weblogic_server = 12.2.1.4.0","data_availability_services","snapcenter"],"patched":["spring_framework 5.2.3"],"published":"2020-01-17","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:17:00.760","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-5398","references":[{"url":"https://lists.apache.org/thread.html/r028977b9b9d44a89823639aa3296fb0f0cfdd76b4450df89d3c4fbbf%40%3Cissues.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r0f2d0ae1bad2edb3d4a863d77f3097b5e88cfbdae7b809f4f42d6aad%40%3Cissues.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r0f3530f7cb510036e497532ffc4e0bd0b882940448cf4e233994b08b%40%3Ccommits.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r1accbd4f31ad2f40e1661d70a4510a584eb3efd1e32e8660ccf46676%40%3Ccommits.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r1bc5d673c01cfbb8e4a91914e9748ead3e5f56b61bca54d314c0419b%40%3Cissues.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r1c679c43fa4f7846d748a937955c7921436d1b315445978254442163%40%3Ccommits.ambari.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r1eccdbd7986618a7319ee7a533bd9d9bf6e8678e59dd4cca9b5b2d7a%40%3Cissues.ambari.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r27552d2fa10d96f2810c50d16ad1fd1899e37796c81a0c5e7585a02d%40%3Cdev.rocketmq.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r2dfd5b331b46d3f90c4dd63a060e9f04300468293874bd7e41af7163%40%3Cissues.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r3765353ff434fd00d8fa5a44734b3625a06eeb2a3fb468da7dfae134%40%3Ccommits.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r4639e821ef9ca6ca10887988f410a60261400a7766560e7a97a22efc%40%3Ccommits.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r4b1886e82cc98ef38f582fef7d4ea722e3fcf46637cd4674926ba682%40%3Cissues.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r5c95eff679dfc642e9e4ab5ac6d202248a59cb1e9457cfbe8b729ac5%40%3Cissues.ambari.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r645408661a8df9158f49e337072df39838fa76da629a7e25a20928a6%40%3Cdev.rocketmq.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r6dac0e365d1b2df9a7ffca12b4195181ec14ff0abdf59e1fdb088ce5%40%3Ccommits.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r712a6fce928e24e7b6ec30994a7e115a70f1f6e4cf2c2fbf0347ce46%40%3Ccommits.servicecomb.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r7361bfe84bde9d233f9800c3a96673e7bd81207549ced0236f07a29d%40%3Cissues.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r74f81f93a9b69140fe41e236afa7cbe8dfa75692e7ab31a468fddaa0%40%3Ccommits.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r7d5e518088e2e778928b02bcd3be3b948b59acefe2f0ebb57ec2ebb0%40%3Ccommits.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r8736185eb921022225a83e56d7285a217fd83f5524bd64a6ca3bf5cc%40%3Cissues.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r881fb5a95ab251106fed38f836257276feb026bfe01290e72ff91c2a%40%3Ccommits.servicecomb.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r8b496b1743d128e6861ee0ed3c3c48cc56c505b38f84fa5baf7ae33a%40%3Cdev.ambari.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r8cc37a60a5056351377ee5f1258f2a4fdd39822a257838ba6bcc1e88%40%3Ccommits.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r9f13cccb214495e14648d2c9b8f2c6072fd5219e74502dd35ede81e1%40%3Cdev.ambari.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r9fb1ee08cf337d16c3364feb0f35a072438c1a956afd7b77859aa090%40%3Cissues.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/ra996b56e1f5ab2fed235a8b91fa0cc3cf34c2e9fee290b7fa4380a0d%40%3Ccommits.servicecomb.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/rab0de39839b4c208dcd73f01e12899dc453361935a816a784548e048%40%3Cissues.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/rb4d1fc078f086ec2e98b2693e8b358e58a6a4ef903ceed93a1ee2b18%40%3Ccommits.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/rc05acaacad089613e9642f939b3a44f7199b5537493945c3e045287f%40%3Cdev.geode.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/rc9c7f96f08c8554225dba9050ea5e64bebc129d0d836303143fe3160%40%3Cdev.rocketmq.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/rdcaadaa9a68b31b7d093d76eacfaacf6c7a819f976b595c75ad2d4dc%40%3Cdev.geode.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/rded5291e25a4c4085a6d43cf262e479140198bf4eabb84986e0a1ef3%40%3Cdev.rocketmq.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/reaa8a6674baf2724b1b88a621b0d72d9f7a6f5577c88759842c16eb6%40%3Ccommits.karaf.apache.org%3E","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/rf8dc72b974ee74f17bce661ea7d124e733a1f4c4f236354ac0cf48e8%40%3Ccommits.camel.apache.org%3E","label":"security@pivotal.io"},{"url":"https://pivotal.io/security/cve-2020-5398","label":"security@pivotal.io"},{"url":"https://security.netapp.com/advisory/ntap-20210917-0006/","label":"security@pivotal.io"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"security@pivotal.io"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"security@pivotal.io"},{"url":"https://www.oracle.com/security-alerts/cpuapr2020.html","label":"security@pivotal.io"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"security@pivotal.io"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"security@pivotal.io"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"security@pivotal.io"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"security@pivotal.io"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"security@pivotal.io"},{"url":"https://lists.apache.org/thread.html/r028977b9b9d44a89823639aa3296fb0f0cfdd76b4450df89d3c4fbbf%40%3Cissues.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r0f2d0ae1bad2edb3d4a863d77f3097b5e88cfbdae7b809f4f42d6aad%40%3Cissues.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r0f3530f7cb510036e497532ffc4e0bd0b882940448cf4e233994b08b%40%3Ccommits.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r1accbd4f31ad2f40e1661d70a4510a584eb3efd1e32e8660ccf46676%40%3Ccommits.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r1bc5d673c01cfbb8e4a91914e9748ead3e5f56b61bca54d314c0419b%40%3Cissues.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r1c679c43fa4f7846d748a937955c7921436d1b315445978254442163%40%3Ccommits.ambari.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r1eccdbd7986618a7319ee7a533bd9d9bf6e8678e59dd4cca9b5b2d7a%40%3Cissues.ambari.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r27552d2fa10d96f2810c50d16ad1fd1899e37796c81a0c5e7585a02d%40%3Cdev.rocketmq.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r2dfd5b331b46d3f90c4dd63a060e9f04300468293874bd7e41af7163%40%3Cissues.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r3765353ff434fd00d8fa5a44734b3625a06eeb2a3fb468da7dfae134%40%3Ccommits.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r4639e821ef9ca6ca10887988f410a60261400a7766560e7a97a22efc%40%3Ccommits.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r4b1886e82cc98ef38f582fef7d4ea722e3fcf46637cd4674926ba682%40%3Cissues.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r5c95eff679dfc642e9e4ab5ac6d202248a59cb1e9457cfbe8b729ac5%40%3Cissues.ambari.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r645408661a8df9158f49e337072df39838fa76da629a7e25a20928a6%40%3Cdev.rocketmq.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r6dac0e365d1b2df9a7ffca12b4195181ec14ff0abdf59e1fdb088ce5%40%3Ccommits.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r712a6fce928e24e7b6ec30994a7e115a70f1f6e4cf2c2fbf0347ce46%40%3Ccommits.servicecomb.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r7361bfe84bde9d233f9800c3a96673e7bd81207549ced0236f07a29d%40%3Cissues.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r74f81f93a9b69140fe41e236afa7cbe8dfa75692e7ab31a468fddaa0%40%3Ccommits.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r7d5e518088e2e778928b02bcd3be3b948b59acefe2f0ebb57ec2ebb0%40%3Ccommits.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r8736185eb921022225a83e56d7285a217fd83f5524bd64a6ca3bf5cc%40%3Cissues.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r881fb5a95ab251106fed38f836257276feb026bfe01290e72ff91c2a%40%3Ccommits.servicecomb.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r8b496b1743d128e6861ee0ed3c3c48cc56c505b38f84fa5baf7ae33a%40%3Cdev.ambari.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r8cc37a60a5056351377ee5f1258f2a4fdd39822a257838ba6bcc1e88%40%3Ccommits.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r9f13cccb214495e14648d2c9b8f2c6072fd5219e74502dd35ede81e1%40%3Cdev.ambari.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r9fb1ee08cf337d16c3364feb0f35a072438c1a956afd7b77859aa090%40%3Cissues.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/ra996b56e1f5ab2fed235a8b91fa0cc3cf34c2e9fee290b7fa4380a0d%40%3Ccommits.servicecomb.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rab0de39839b4c208dcd73f01e12899dc453361935a816a784548e048%40%3Cissues.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rb4d1fc078f086ec2e98b2693e8b358e58a6a4ef903ceed93a1ee2b18%40%3Ccommits.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rc05acaacad089613e9642f939b3a44f7199b5537493945c3e045287f%40%3Cdev.geode.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rc9c7f96f08c8554225dba9050ea5e64bebc129d0d836303143fe3160%40%3Cdev.rocketmq.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rdcaadaa9a68b31b7d093d76eacfaacf6c7a819f976b595c75ad2d4dc%40%3Cdev.geode.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rded5291e25a4c4085a6d43cf262e479140198bf4eabb84986e0a1ef3%40%3Cdev.rocketmq.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/reaa8a6674baf2724b1b88a621b0d72d9f7a6f5577c88759842c16eb6%40%3Ccommits.karaf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rf8dc72b974ee74f17bce661ea7d124e733a1f4c4f236354ac0cf48e8%40%3Ccommits.camel.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://pivotal.io/security/cve-2020-5398","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210917-0006/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.88768,"epssPercentile":0.99775,"exploits":{"github":1,"githubRepos":["https://github.com/motikan2010/CVE-2020-5398"],"checkedAt":"2026-10-08T23:17:21.743Z"},"exploitAvailable":true,"ingestedAt":"2026-10-08T23:16:47.302Z","slug":"CVE-2020-5398","body":"## Overview\n\nIn Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a \"Content-Disposition\" header in the response where the filename attribute is derived from user supplied input.\n\n## Affected\n\n- `spring_framework >= 5.0.0, < 5.0.16`\n- `spring_framework >= 5.1.0, < 5.1.13`\n- `spring_framework >= 5.2.0, < 5.2.3`\n- `application_testing_suite = 13.3.0.1`\n- `communications_billing_and_revenue_management_elastic_charging_engine = 11.3`\n- `communications_billing_and_revenue_management_elastic_charging_engine = 12.0`\n- `communications_cloud_native_core_policy = 1.5.0`\n- `communications_diameter_signaling_router >= 8.0.0, <= 8.2.2`\n- `communications_element_manager = 8.1.1`\n- `communications_element_manager = 8.2.0`\n- `communications_element_manager = 8.2.1`\n- `communications_policy_management = 12.5.0`\n- `communications_session_report_manager = 8.1.1`\n- `communications_session_report_manager = 8.2.0`\n- `communications_session_report_manager = 8.2.1`\n- `communications_session_route_manager = 8.1.1`\n- `communications_session_route_manager = 8.2.0`\n- `communications_session_route_manager = 8.2.1`\n- `enterprise_manager_base_platform = 13.2.1.0`\n- `financial_services_regulatory_reporting_with_agilereporter = 8.0.9.2.0`\n- `flexcube_private_banking = 12.0.0`\n- `flexcube_private_banking = 12.1.0`\n- `healthcare_master_person_index = 4.0.2`\n- `insurance_calculation_engine >= 11.0.0, <= 11.3.1`\n- `insurance_policy_administration_j2ee = 10.2.0`\n- `insurance_policy_administration_j2ee = 10.2.4`\n- `insurance_policy_administration_j2ee = 11.0.2`\n- `insurance_policy_administration_j2ee = 11.1.0`\n- `insurance_policy_administration_j2ee = 11.2.0`\n- `insurance_policy_administration_j2ee = 11.2.2.0`\n- `insurance_rules_palette = 10.2.0`\n- `insurance_rules_palette = 10.2.4`\n- `insurance_rules_palette = 11.0.2`\n- `insurance_rules_palette = 11.1.0`\n- `insurance_rules_palette = 11.2.0`\n- `mysql >= 4.0.0, <= 4.0.12`\n- `mysql >= 8.0.0, <= 8.0.20`\n- `rapid_planning = 12.1`\n- `rapid_planning = 12.2`\n- `retail_assortment_planning = 15.0`\n- `retail_assortment_planning = 16.0`\n- `retail_back_office = 14.1`\n- `retail_bulk_data_integration = 16.0.3.0`\n- `retail_central_office = 14.1`\n- `retail_financial_integration = 15.0`\n- `retail_financial_integration = 16.0`\n- `retail_integration_bus = 15.0.3`\n- `retail_integration_bus = 16.0.3`\n- `retail_order_broker = 15.0`\n- `retail_order_broker = 16.0`\n- `retail_point-of-service = 14.1`\n- `retail_predictive_application_server = 14.0.3`\n- `retail_predictive_application_server = 14.1.3.0`\n- `retail_predictive_application_server = 15.0.3`\n- `retail_predictive_application_server = 16.0.3.0`\n- `retail_returns_management = 14.1`\n- `retail_service_backbone = 15.0`\n- `retail_service_backbone = 16.0`\n- `siebel_engineering_-_installer_&_deployment <= 2.1.1`\n- `weblogic_server = 12.2.1.3.0`\n- `weblogic_server = 12.2.1.4.0`\n- `data_availability_services`\n- `snapcenter`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `spring_framework 5.2.3`","depth":"midnight","depthScore":71,"depthScoreParts":{"impact":41.3,"likelihood":17.8,"exploitation":12,"ransomware":0},"changes":[]}