Description
VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.
Remediation
References
http://osvdb.org/68931
http://secunia.com/advisories/42024
http://www.securityfocus.com/archive/1/514517/100/0/threaded
http://www.securityfocus.com/bid/44496
http://www.springsource.com/security/cve-2010-3700
https://issues.apache.org/bugzilla/show_bug.cgi?id=25015
Related Vulnerabilities
CVE-2016-6811 Vulnerability in maven package org.apache.hadoop:hadoop-yarn-server-nodemanager
CVE-2013-1768 Vulnerability in maven package org.apache.openjpa:openjpa
CVE-2012-4387 Vulnerability in maven package org.apache.struts.xwork:xwork-core
CVE-2016-3084 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server
CVE-2014-8115 Vulnerability in maven package org.kie:kie-drools-wb-distribution-wars