Disclosure summary
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
Source-reported weakness categories
NVD-CWE-noinfo
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2020-5421
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| vmware | spring_framework | * {"versionStartIncluding":"5.2.0","versionEndExcluding":"5.2.9"} |
| oracle | commerce_guided_search | 11.3.2 |
| oracle | communications_brm | 11.3.0.9 |
| oracle | communications_brm | 12.0.0.3 |
| oracle | communications_design_studio | 7.3.4 |
| oracle | communications_design_studio | 7.3.5 |
| oracle | communications_design_studio | 7.4.0 |
| oracle | communications_session_report_manager | * {"versionStartIncluding":"8.2.1","versionEndIncluding":"8.2.2.1"} |
| oracle | communications_unified_inventory_management | 7.3.4 |
| oracle | communications_unified_inventory_management | 7.3.5 |
| oracle | endeca_information_discovery_integrator | 3.2.0 |
| oracle | enterprise_data_quality | 12.2.1.3.0 |
| oracle | enterprise_data_quality | 12.2.1.4.0 |
| oracle | financial_services_analytical_applications_infrastructure | * {"versionStartIncluding":"8.0.6","versionEndIncluding":"8.1.0"} |
| oracle | flexcube_private_banking | 12.0.0 |
| oracle | flexcube_private_banking | 12.1.0 |
| oracle | fusion_middleware | 12.2.1.3.0 |
| oracle | fusion_middleware | 12.2.1.4.0 |
| oracle | goldengate_application_adapters | 19.1.0.0.0 |
| oracle | healthcare_master_person_index | 4.0.2.5 |
| oracle | hyperion_infrastructure_technology | 11.1.2.4 |
| oracle | insurance_policy_administration | * {"versionStartIncluding":"11.1.0","versionEndIncluding":"11.3.0"} |
| oracle | insurance_policy_administration | 10.2 |
| oracle | insurance_policy_administration | 10.2.4 |
| oracle | insurance_policy_administration | 11.0.2 |
| oracle | insurance_rules_palette | * {"versionStartIncluding":"11.1.0","versionEndIncluding":"11.3.0"} |
| oracle | insurance_rules_palette | 10.2.0 |
| oracle | insurance_rules_palette | 10.2.4 |
| oracle | insurance_rules_palette | 11.0.2 |
| oracle | mysql_enterprise_monitor | * {"versionEndIncluding":"8.0.22"} |
| oracle | mysql_enterprise_monitor | 8.0.23 |
| oracle | primavera_gateway | * {"versionStartIncluding":"19.12.0","versionEndIncluding":"19.12.10"} |
| oracle | primavera_p6_enterprise_project_portfolio_management | * {"versionStartIncluding":"19.12.0","versionEndIncluding":"19.12.10"} |
| oracle | retail_assortment_planning | 16.0.3.0 |
| oracle | retail_bulk_data_integration | 16.0.3.0 |
| oracle | retail_customer_engagement | * {"versionStartIncluding":"16.0","versionEndIncluding":"19.0"} |
| oracle | retail_customer_management_and_segmentation_foundation | * {"versionStartIncluding":"16.0","versionEndIncluding":"19.0"} |
| oracle | retail_financial_integration | 14.1.3 |
| oracle | retail_financial_integration | 15.0.3 |
| oracle | retail_financial_integration | 16.0.3 |
| oracle | retail_integration_bus | 14.1.3 |
| oracle | retail_integration_bus | 15.0.3 |
| oracle | retail_integration_bus | 16.0.3 |
| oracle | retail_invoice_matching | 14.0 |
| oracle | retail_invoice_matching | 14.1 |
| oracle | retail_merchandising_system | 16.0.3 |
| oracle | retail_order_broker | 15.0 |
| oracle | retail_order_broker | 16.0 |
| oracle | retail_predictive_application_server | 14.1 |
| oracle | retail_returns_management | 14.1 |
| oracle | retail_service_backbone | 14.1.3 |
| oracle | retail_service_backbone | 15.0.3 |
| oracle | retail_service_backbone | 16.0.3 |
| oracle | retail_xstore_point_of_service | 15.0.4 |
| oracle | retail_xstore_point_of_service | 16.0.6 |
| oracle | retail_xstore_point_of_service | 17.0.4 |
| oracle | retail_xstore_point_of_service | 18.0.3 |
| oracle | retail_xstore_point_of_service | 19.0.2 |
| oracle | storagetek_acsls | 8.5.1 |
| oracle | storagetek_tape_analytics_sw_tool | 2.3 |
| oracle | weblogic_server | 10.3.6.0.0 |
| oracle | weblogic_server | 12.1.3.0.0 |
| oracle | weblogic_server | 12.2.1.3.0 |
| oracle | weblogic_server | 12.2.1.4.0 |
| oracle | weblogic_server | 14.1.1.0.0 |
| netapp | oncommand_insight | - |
| netapp | snap_creator_framework | - |
| netapp | snapcenter | - |
Original records & references
- NIST NVD record
- CVE Program record
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- security.netapp.com — Third Party Advisory
- tanzu.vmware.com — Vendor Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Not Applicable, Third Party Advisory
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- security.netapp.com — Third Party Advisory
- tanzu.vmware.com — Vendor Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Not Applicable, Third Party Advisory
PUBLISHED 2020-09-19T00:15:11-04:00
MODIFIED 2026-10-08T17:17:30-04:00
INGESTED 2026-10-10T20:50:19-04:00