CVE-2016-9879 describes a security bypass vulnerability in Pivotal Spring Security versions prior to 3.2.10, 4.1.4, and 4.2.1, affecting products like IBM WebSphere Application Server. Attackers can bypass security constraints by adding URL path parameters with encoded slashes, exploiting inconsistencies in Servlet Specification handling of path parameters. This vulnerability has a CVSS v3 score of 7.5 (High), indicating a network-exploitable, low-complexity attack that can lead to high integrity impact without user interaction. While the vulnerability is known to affect IBM WebSphere Application Server 8.5.x, there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.2.0CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:3.2.0:*:*:*:*:*:*:* | ||
3.2.1CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:3.2.1:*:*:*:*:*:*:* | ||
3.2.2CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:3.2.2:*:*:*:*:*:*:* | ||
3.2.3CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:3.2.3:*:*:*:*:*:*:* | ||
3.2.4CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:3.2.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.