VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:19
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/68931 - | |
References | () http://secunia.com/advisories/42024 - | |
References | () http://www.securityfocus.com/archive/1/514517/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/44496 - | |
References | () http://www.springsource.com/security/cve-2010-3700 - | |
References | () https://issues.apache.org/bugzilla/show_bug.cgi?id=25015 - |
Information
Published : 2010-10-29 19:00
Updated : 2024-11-21 01:19
NVD link : CVE-2010-3700
Mitre link : CVE-2010-3700
CVE.ORG link : CVE-2010-3700
JSON object : View
Products Affected
vmware
- springsource_spring_security
acegisecurity
- acegi-security
ibm
- websphere_application_server
CWE
CWE-264
Permissions, Privileges, and Access Controls