GHSA-rv39-3qh7-9v7w · Severity: medium · Ecosystem: maven — Improper Input Validation in Spring Framework
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
Conclusion & alert: CVE-2020-5421 is rated Moderate Risk (54.3/100): CVSS Medium severity, with high exploitation likelihood (EPSS 10.74%, 95th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 63.83% | 10.74% | -53.09% |
| 2 | 2026-03-22 | 68.07% | 63.83% | -4.25% |
| 3 | 2026-03-18 | — | 68.07% | — |
Full EPSS history (44 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
1.3 | 4.7 | [email protected] |
| 8.7 | 3.0 | HIGH |
|
2.3 | 5.8 | [email protected] |
| 3.6 | 2.0 | LOW |
|
3.9 | 4.9 | [email protected] |
GHSA-rv39-3qh7-9v7w · Severity: medium · Ecosystem: maven — Improper Input Validation in Spring Framework
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2020-5421 unimportant priority: Debian including 1 source packages (libspring-java), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2020-5421 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2020-5421 |
ubuntu
|
medium | CVE-2020-5421 medium priority: Ubuntu including 1 source packages (libspring-java), 16 status rows across 16 suites (bionic, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): ignored 8, needs-triage 8. | https://ubuntu.com/security/CVE-2020-5421 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| vmware | spring_framework | < 4.3.29 | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* |
| vmware | spring_framework | >= 5.0.0, < 5.0.19 | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* |
| vmware | spring_framework | >= 5.1.0, < 5.1.18 | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* |
| vmware | spring_framework | >= 5.2.0, < 5.2.9 | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* |
| oracle | commerce_guided_search | 11.3.2 | cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:* |
| oracle | communications_brm | 11.3.0.9 | cpe:2.3:a:oracle:communications_brm:11.3.0.9:*:*:*:*:*:*:* |
| oracle | communications_brm | 12.0.0.3 | cpe:2.3:a:oracle:communications_brm:12.0.0.3:*:*:*:*:*:*:* |
| oracle | communications_design_studio | 7.3.4 | cpe:2.3:a:oracle:communications_design_studio:7.3.4:*:*:*:*:*:*:* |
| oracle | communications_design_studio | 7.3.5 | cpe:2.3:a:oracle:communications_design_studio:7.3.5:*:*:*:*:*:*:* |
| oracle | communications_design_studio | 7.4.0 | cpe:2.3:a:oracle:communications_design_studio:7.4.0:*:*:*:*:*:*:* |
| oracle | communications_session_report_manager | >= 8.2.1, <= 8.2.2.1 | cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:* |
| oracle | communications_unified_inventory_management | 7.3.4 | cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.4:*:*:*:*:*:*:* |
| oracle | communications_unified_inventory_management | 7.3.5 | cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.5:*:*:*:*:*:*:* |
| oracle | endeca_information_discovery_integrator | 3.2.0 | cpe:2.3:a:oracle:endeca_information_discovery_integrator:3.2.0:*:*:*:*:*:*:* |
| oracle | enterprise_data_quality | 12.2.1.3.0 | cpe:2.3:a:oracle:enterprise_data_quality:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | enterprise_data_quality | 12.2.1.4.0 | cpe:2.3:a:oracle:enterprise_data_quality:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | financial_services_analytical_applications_infrastructure | >= 8.0.6, <= 8.1.0 | cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:* |
| oracle | flexcube_private_banking | 12.0.0 | cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:* |
| oracle | flexcube_private_banking | 12.1.0 | cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:* |
| oracle | fusion_middleware | 12.2.1.3.0 | cpe:2.3:a:oracle:fusion_middleware:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | fusion_middleware | 12.2.1.4.0 | cpe:2.3:a:oracle:fusion_middleware:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | goldengate_application_adapters | 19.1.0.0.0 | cpe:2.3:a:oracle:goldengate_application_adapters:19.1.0.0.0:*:*:*:*:*:*:* |
| oracle | healthcare_master_person_index | 4.0.2.5 | cpe:2.3:a:oracle:healthcare_master_person_index:4.0.2.5:*:*:*:*:*:*:* |
| oracle | hyperion_infrastructure_technology | 11.1.2.4 | cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.1.2.4:*:*:*:*:*:*:* |
| oracle | insurance_policy_administration | >= 11.1.0, <= 11.3.0 | cpe:2.3:a:oracle:insurance_policy_administration:*:*:*:*:*:*:*:* |
| oracle | insurance_policy_administration | 10.2 | cpe:2.3:a:oracle:insurance_policy_administration:10.2:*:*:*:*:*:*:* |
| oracle | insurance_policy_administration | 10.2.4 | cpe:2.3:a:oracle:insurance_policy_administration:10.2.4:*:*:*:*:*:*:* |
| oracle | insurance_policy_administration | 11.0.2 | cpe:2.3:a:oracle:insurance_policy_administration:11.0.2:*:*:*:*:*:*:* |
| oracle | insurance_rules_palette | >= 11.1.0, <= 11.3.0 | cpe:2.3:a:oracle:insurance_rules_palette:*:*:*:*:*:*:*:* |
| oracle | insurance_rules_palette | 10.2.0 | cpe:2.3:a:oracle:insurance_rules_palette:10.2.0:*:*:*:*:*:*:* |
| oracle | insurance_rules_palette | 10.2.4 | cpe:2.3:a:oracle:insurance_rules_palette:10.2.4:*:*:*:*:*:*:* |
| oracle | insurance_rules_palette | 11.0.2 | cpe:2.3:a:oracle:insurance_rules_palette:11.0.2:*:*:*:*:*:*:* |
| oracle | mysql_enterprise_monitor | <= 8.0.22 | cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* |
| oracle | mysql_enterprise_monitor | 8.0.23 | cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.23:*:*:*:*:*:*:* |
| oracle | primavera_gateway | >= 16.2.0, <= 16.2.11 | cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* |
| oracle | primavera_gateway | >= 17.12.0, <= 17.12.9 | cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* |
| oracle | primavera_gateway | >= 18.8.0, <= 18.8.10 | cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* |
| oracle | primavera_gateway | >= 19.12.0, <= 19.12.10 | cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* |
| oracle | primavera_p6_enterprise_project_portfolio_management | >= 16.1.0, <= 16.2.20 | cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:*:*:*:*:*:*:*:* |
| oracle | primavera_p6_enterprise_project_portfolio_management | >= 17.1.0, <= 17.12.19 | cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:*:*:*:*:*:*:*:* |
| oracle | primavera_p6_enterprise_project_portfolio_management | >= 18.1.0, <= 18.8.21 | cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:*:*:*:*:*:*:*:* |
| oracle | primavera_p6_enterprise_project_portfolio_management | >= 19.12.0, <= 19.12.10 | cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:*:*:*:*:*:*:*:* |
| oracle | retail_assortment_planning | 16.0.3.0 | cpe:2.3:a:oracle:retail_assortment_planning:16.0.3.0:*:*:*:*:*:*:* |
| oracle | retail_bulk_data_integration | 16.0.3.0 | cpe:2.3:a:oracle:retail_bulk_data_integration:16.0.3.0:*:*:*:*:*:*:* |
| oracle | retail_customer_engagement | >= 16.0, <= 19.0 | cpe:2.3:a:oracle:retail_customer_engagement:*:*:*:*:*:*:*:* |
| oracle | retail_customer_management_and_segmentation_foundation | >= 16.0, <= 19.0 | cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:*:*:*:*:*:*:*:* |
| oracle | retail_financial_integration | 14.1.3 | cpe:2.3:a:oracle:retail_financial_integration:14.1.3:*:*:*:*:*:*:* |
| oracle | retail_financial_integration | 15.0.3 | cpe:2.3:a:oracle:retail_financial_integration:15.0.3:*:*:*:*:*:*:* |
| oracle | retail_financial_integration | 16.0.3 | cpe:2.3:a:oracle:retail_financial_integration:16.0.3:*:*:*:*:*:*:* |
| oracle | retail_integration_bus | 14.1.3 | cpe:2.3:a:oracle:retail_integration_bus:14.1.3:*:*:*:*:*:*:* |
| oracle | retail_integration_bus | 15.0.3 | cpe:2.3:a:oracle:retail_integration_bus:15.0.3:*:*:*:*:*:*:* |
| oracle | retail_integration_bus | 16.0.3 | cpe:2.3:a:oracle:retail_integration_bus:16.0.3:*:*:*:*:*:*:* |
| oracle | retail_invoice_matching | 14.0 | cpe:2.3:a:oracle:retail_invoice_matching:14.0:*:*:*:*:*:*:* |
| oracle | retail_invoice_matching | 14.1 | cpe:2.3:a:oracle:retail_invoice_matching:14.1:*:*:*:*:*:*:* |
| oracle | retail_merchandising_system | 16.0.3 | cpe:2.3:a:oracle:retail_merchandising_system:16.0.3:*:*:*:*:*:*:* |
| oracle | retail_order_broker | 15.0 | cpe:2.3:a:oracle:retail_order_broker:15.0:*:*:*:*:*:*:* |
| oracle | retail_order_broker | 16.0 | cpe:2.3:a:oracle:retail_order_broker:16.0:*:*:*:*:*:*:* |
| oracle | retail_predictive_application_server | 14.1 | cpe:2.3:a:oracle:retail_predictive_application_server:14.1:*:*:*:*:*:*:* |
| oracle | retail_returns_management | 14.1 | cpe:2.3:a:oracle:retail_returns_management:14.1:*:*:*:*:*:*:* |
| oracle | retail_service_backbone | 14.1.3 | cpe:2.3:a:oracle:retail_service_backbone:14.1.3:*:*:*:*:*:*:* |
| oracle | retail_service_backbone | 15.0.3 | cpe:2.3:a:oracle:retail_service_backbone:15.0.3:*:*:*:*:*:*:* |
| oracle | retail_service_backbone | 16.0.3 | cpe:2.3:a:oracle:retail_service_backbone:16.0.3:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 15.0.4 | cpe:2.3:a:oracle:retail_xstore_point_of_service:15.0.4:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 16.0.6 | cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0.6:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 17.0.4 | cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0.4:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 18.0.3 | cpe:2.3:a:oracle:retail_xstore_point_of_service:18.0.3:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 19.0.2 | cpe:2.3:a:oracle:retail_xstore_point_of_service:19.0.2:*:*:*:*:*:*:* |
| oracle | storagetek_acsls | 8.5.1 | cpe:2.3:a:oracle:storagetek_acsls:8.5.1:*:*:*:*:*:*:* |
| oracle | storagetek_tape_analytics_sw_tool | 2.3 | cpe:2.3:a:oracle:storagetek_tape_analytics_sw_tool:2.3:*:*:*:*:*:*:* |
| oracle | weblogic_server | 10.3.6.0.0 | cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:* |
| oracle | weblogic_server | 12.1.3.0.0 | cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:* |
| oracle | weblogic_server | 12.2.1.3.0 | cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | weblogic_server | 12.2.1.4.0 | cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | weblogic_server | 14.1.1.0.0 | cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:* |
| netapp | oncommand_insight | — | cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* |
| netapp | snap_creator_framework | — | cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:* |
| netapp | snapcenter | — | cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:* |