Moderate severityNVD Advisory· Published Jun 21, 2010· Updated Jun 16, 2026
CVE-2010-1622
CVE-2010-1622
Description
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework:springMaven | >= 2.5.0, < 2.5.7 | 2.5.7 |
org.springframework:springMaven | >= 3.0.0, < 3.0.3 | 3.0.3 |
Affected products
15cpe:2.3:a:oracle:fusion_middleware:11.1.1.6.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:fusion_middleware:11.1.1.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:fusion_middleware:11.1.1.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:fusion_middleware:7.6.2:*:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:2.5.0:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:springsource:spring_framework:2.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:springsource:spring_framework:2.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:springsource:spring_framework:2.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:springsource:spring_framework:2.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:springsource:spring_framework:2.5.4:*:*:*:*:*:*:*
- cpe:2.3:a:springsource:spring_framework:2.5.5:*:*:*:*:*:*:*
- cpe:2.3:a:springsource:spring_framework:2.5.6:*:*:*:*:*:*:*
- cpe:2.3:a:springsource:spring_framework:2.5.7:*:*:*:*:*:*:*
- cpe:2.3:a:springsource:spring_framework:3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:springsource:spring_framework:3.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:springsource:spring_framework:3.0.2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
25- www.exploit-db.com/exploits/13918nvdExploitWEB
- www.securityfocus.com/archive/1/511877nvdExploit
- www.springsource.com/security/cve-2010-1622nvdExploitVendor Advisory
- geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.htmlnvdVendor AdvisoryWEB
- geronimo.apache.org/21x-security-report.htmlnvdVendor AdvisoryWEB
- geronimo.apache.org/22x-security-report.htmlnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-vpr3-f594-mg5gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2010-1622ghsaADVISORY
- www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlnvdWEB
- www.redhat.com/support/errata/RHSA-2011-0175.htmlnvdWEB
- access.redhat.com/errata/RHSA-2011:0175ghsaWEB
- access.redhat.com/security/cve/CVE-2010-1622ghsaWEB
- bugzilla.redhat.com/show_bug.cgighsaWEB
- github.com/spring-projects/spring-framework/commit/3a5af35d37c79d0644d49b93f792a4c18fe8eb71ghsaWEB
- seclists.org/fulldisclosure/2010/Jun/456ghsaWEB
- web.archive.org/web/20100623011648/http://www.springsource.com/security/cve-2010-1622ghsaWEB
- web.archive.org/web/20161014113129/http://www.securitytracker.com/id/1033898ghsaWEB
- web.archive.org/web/20200227210033/http://www.securityfocus.com/archive/1/511877ghsaWEB
- web.archive.org/web/20200228060816/http://www.securityfocus.com/bid/40954ghsaWEB
- secunia.com/advisories/41016nvd
- secunia.com/advisories/41025nvd
- secunia.com/advisories/43087nvd
- www.securityfocus.com/bid/40954nvd
- www.securitytracker.com/id/1033898nvd
- www.vupen.com/english/advisories/2011/0237nvd
News mentions
0No linked articles in our index yet.