SB2016122321 - Fedora 25 update for springframework
Published: December 23, 2016 Updated: April 24, 2025
Security Bulletin ID
SB2016122321
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Physical access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Path traversal (CVE-ID: CVE-2016-9878)
The vulnerability allows a physical authenticated attacker to obtain potentially sensitive information on the target system.The weakness exists due to improper sanitization of paths provided to the ResourceServlet. A physical attacker can trigger path traversal and gain access to potentially sensitive information.
Remediation
Install update from vendor's website.