A PTC Technical Support Account Manager (TSAM) is your company's personal advocate for leveraging the breadth and depth of PTC's Global Support System, ensuring that your critical issues receive the appropriate attention quickly and accurately.
Description: A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
Mitigation: Update to Spring Framework 5.3.18
Applicability: See Resolution for Winchill RV&S 13.0
Description: In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in access to local resources.
Mitigation: Users of affected versions should upgrade to 3.1.7, 3.2.3. No other steps are necessary.
Applicability: Not applicable to WRV&S. No Impact.
Description: In Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service condition.
Mitigation: Users of affected versions should upgrade to 5.3.17+. No other steps are necessary.
Applicability: See Resolution
Esta é uma versão em PDF do artigo 366731 e pode estar desatualizada. Para a versão mais recente, clique CS366731
Hi , help us improve this article.
Flagging content with inappropriate information will hide this article from public view for you and other customers, do you want to continue?
Acesso à base de conhecimento
Log in to:
Faça login para:
Ler todo o conteúdo deste artigo
Descobrir conteúdo relacionado a este tópico
Pesquisar todas as nossas fontes de conteúdo (Base de conhecimento, Help Centers, Tópicos da comunidade.)