VYPR
High severity7.5NVD Advisory· Published Dec 29, 2016· Updated May 6, 2026

CVE-2016-9878

CVE-2016-9878

Description

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.springframework:spring-webmvcMaven
< 3.2.183.2.18
org.springframework:spring-webmvcMaven
>= 4.2.0, < 4.2.94.2.9
org.springframework:spring-webmvcMaven
>= 4.3.0, < 4.3.54.3.5

Affected products

32
  • cpe:2.3:a:pivotal_software:spring_framework:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:pivotal_software:spring_framework:*:*:*:*:*:*:*:*range: <=3.2.0
    • cpe:2.3:a:pivotal_software:spring_framework:4.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:pivotal_software:spring_framework:4.3.0:*:*:*:*:*:*:*
  • cpe:2.3:a:vmware:spring_framework:3.2.1:*:*:*:*:*:*:*+ 28 more
    • cpe:2.3:a:vmware:spring_framework:3.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:3.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:3.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:3.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:3.2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:3.2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:3.2.7:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:3.2.8:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:3.2.13:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:3.2.14:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:3.2.15:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:3.2.16:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:3.2.17:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:3.2.9:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:3.2.10:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:3.2.11:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:3.2.12:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:4.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:4.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:4.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:4.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:4.2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:4.2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:4.2.7:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:4.2.8:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:4.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:4.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:4.3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:vmware:spring_framework:4.3.4:*:*:*:*:*:*:*

Patches

3

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

17

News mentions

0

No linked articles in our index yet.