WID-SEC-W-2026-2955

Vulnerability from csaf_certbund - Published: 2026-08-20 22:00 - Updated: 2026-08-27 22:00
Summary
VMware Tanzu Spring Framework: Mehrere Schwachstellen
Severity
Hoch
Notes
Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen.
Produktbeschreibung: Das Spring Framework bietet ein Entwicklungsmodell für Java mit Infrastrukturunterstützung auf Anwendungsebene.
Angriff: Ein Angreifer kann mehrere Schwachstellen in VMware Tanzu Spring Framework ausnutzen, um beliebigen Code auszuführen, Cross-Site-Scripting-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen, sensible Informationen offenzulegen, offene Weiterleitungen durchzuführen, Daten zu manipulieren oder Denial-of-Service-Zustände zu verursachen.
Betroffene Betriebssysteme: - Sonstiges - UNIX - Windows
Affected products
Product Identifier Version Remediation
VMware Tanzu Spring Framework Enterprise Support Only <5.2.26
VMware Tanzu / Spring Framework
Enterprise Support Only <5.2.26
VMware Tanzu Spring Framework Enterprise Support Only <5.3.50
VMware Tanzu / Spring Framework
Enterprise Support Only <5.3.50
VMware Tanzu Spring Framework OSS <7.0.9
VMware Tanzu / Spring Framework
OSS <7.0.9
VMware Tanzu Spring Framework Enterprise Support Only <6.2.20
VMware Tanzu / Spring Framework
Enterprise Support Only <6.2.20
VMware Tanzu Spring Framework Enterprise Support Only <7.0.8.1
VMware Tanzu / Spring Framework
Enterprise Support Only <7.0.8.1
VMware Tanzu Spring Framework Enterprise Support Only <6.0.31
VMware Tanzu / Spring Framework
Enterprise Support Only <6.0.31
VMware Tanzu Spring Framework Enterprise Support Only <6.1.29
VMware Tanzu / Spring Framework
Enterprise Support Only <6.1.29
Affected products
Known affected 7 products, the same list as for CVE-2026-47883
Affected products
Known affected 7 products, the same list as for CVE-2026-47883
Affected products
Known affected 7 products, the same list as for CVE-2026-47883
Affected products
Known affected 7 products, the same list as for CVE-2026-47883
Affected products
Known affected 7 products, the same list as for CVE-2026-47883
Affected products
Known affected 7 products, the same list as for CVE-2026-47883
Affected products
Known affected 7 products, the same list as for CVE-2026-47883
Affected products
Known affected 7 products, the same list as for CVE-2026-47883
Affected products
Known affected 7 products, the same list as for CVE-2026-47883
Affected products
Known affected 7 products, the same list as for CVE-2026-47883
Affected products
Known affected 7 products, the same list as for CVE-2026-47883
Affected products
Known affected 7 products, the same list as for CVE-2026-47883
Affected products
Known affected 7 products, the same list as for CVE-2026-47883
Affected products
Known affected 7 products, the same list as for CVE-2026-47883
Affected products
Known affected 7 products, the same list as for CVE-2026-47883

{
  "document": {
    "aggregate_severity": {
      "text": "hoch"
    },
    "category": "csaf_base",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "de-DE",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "Das BSI ist als Anbieter f\u00fcr die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch daf\u00fcr verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgf\u00e4ltig im Einzelfall zu pr\u00fcfen."
      },
      {
        "category": "description",
        "text": "Das Spring Framework bietet ein Entwicklungsmodell f\u00fcr Java mit Infrastrukturunterst\u00fctzung auf Anwendungsebene.",
        "title": "Produktbeschreibung"
      },
      {
        "category": "summary",
        "text": "Ein Angreifer kann mehrere Schwachstellen in VMware Tanzu Spring Framework ausnutzen, um beliebigen Code auszuf\u00fchren, Cross-Site-Scripting-Angriffe durchzuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen, sensible Informationen offenzulegen, offene Weiterleitungen durchzuf\u00fchren, Daten zu manipulieren oder Denial-of-Service-Zust\u00e4nde zu verursachen.",
        "title": "Angriff"
      },
      {
        "category": "general",
        "text": "- Sonstiges\n- UNIX\n- Windows",
        "title": "Betroffene Betriebssysteme"
      }
    ],
    "publisher": {
      "category": "other",
      "contact_details": "csaf-provider@cert-bund.de",
      "name": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
      "namespace": "https://www.bsi.bund.de"
    },
    "references": [
      {
        "category": "self",
        "summary": "WID-SEC-W-2026-2955 - CSAF Version",
        "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2955.json"
      },
      {
        "category": "self",
        "summary": "WID-SEC-2026-2955 - Portal Version",
        "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2955"
      },
      {
        "category": "external",
        "summary": "Spring Security Advisory CVE-2026-47883 vom 2026-08-20",
        "url": "https://spring.io/security/cve-2026-47883"
      },
      {
        "category": "external",
        "summary": "Spring Security Advisory CVE-2026-47884 vom 2026-08-20",
        "url": "https://spring.io/security/cve-2026-47884"
      },
      {
        "category": "external",
        "summary": "Spring Security Advisory CVE-2026-47885 vom 2026-08-20",
        "url": "https://spring.io/security/cve-2026-47885"
      },
      {
        "category": "external",
        "summary": "Spring Security Advisory CVE-2026-47886 vom 2026-08-20",
        "url": "https://spring.io/security/cve-2026-47886"
      },
      {
        "category": "external",
        "summary": "Spring Security Advisory CVE-2026-47887 vom 2026-08-20",
        "url": "https://spring.io/security/cve-2026-47887"
      },
      {
        "category": "external",
        "summary": "Spring Security Advisory CVE-2026-47888 vom 2026-08-20",
        "url": "https://spring.io/security/cve-2026-47888"
      },
      {
        "category": "external",
        "summary": "Spring Security Advisory CVE-2026-47889 vom 2026-08-20",
        "url": "https://spring.io/security/cve-2026-47889"
      },
      {
        "category": "external",
        "summary": "Spring Security Advisory CVE-2026-47890 vom 2026-08-20",
        "url": "https://spring.io/security/cve-2026-47890"
      },
      {
        "category": "external",
        "summary": "Spring Security Advisory CVE-2026-47891 vom 2026-08-20",
        "url": "https://spring.io/security/cve-2026-47891"
      },
      {
        "category": "external",
        "summary": "Spring Security Advisory CVE-2026-47892 vom 2026-08-20",
        "url": "https://spring.io/security/cve-2026-47892"
      },
      {
        "category": "external",
        "summary": "Spring Security Advisory CVE-2026-47893 vom 2026-08-20",
        "url": "https://spring.io/security/cve-2026-47893"
      },
      {
        "category": "external",
        "summary": "Spring Security Advisory CVE-2026-59280 vom 2026-08-20",
        "url": "https://spring.io/security/cve-2026-59280"
      },
      {
        "category": "external",
        "summary": "Spring Security Advisory CVE-2026-59281 vom 2026-08-20",
        "url": "https://spring.io/security/cve-2026-59281"
      },
      {
        "category": "external",
        "summary": "Spring Security Advisory CVE-2026-59282 vom 2026-08-20",
        "url": "https://spring.io/security/cve-2026-59282"
      },
      {
        "category": "external",
        "summary": "Spring Security Advisory CVE-2026-59283 vom 2026-08-20",
        "url": "https://spring.io/security/cve-2026-59283"
      },
      {
        "category": "external",
        "summary": "Spring Security Advisory CVE-2026-59314 vom 2026-08-20",
        "url": "https://spring.io/security/cve-2026-59314"
      }
    ],
    "source_lang": "en-US",
    "title": "VMware Tanzu Spring Framework: Mehrere Schwachstellen",
    "tracking": {
      "current_release_date": "2026-08-27T22:00:00.000+00:00",
      "generator": {
        "date": "2026-08-28T07:46:39.742+00:00",
        "engine": {
          "name": "BSI-WID",
          "version": "1.6.0"
        }
      },
      "id": "WID-SEC-W-2026-2955",
      "initial_release_date": "2026-08-20T22:00:00.000+00:00",
      "revision_history": [
        {
          "date": "2026-08-20T22:00:00.000+00:00",
          "number": "1",
          "summary": "Initiale Fassung"
        },
        {
          "date": "2026-08-26T22:00:00.000+00:00",
          "number": "2",
          "summary": "Referenz(en) aufgenommen: EUVD-2026-66860, EUVD-2026-66859, EUVD-2026-66858, EUVD-2026-66857, EUVD-2026-66856, EUVD-2026-66855, EUVD-2026-66854, EUVD-2026-66853, EUVD-2026-66851"
        },
        {
          "date": "2026-08-27T22:00:00.000+00:00",
          "number": "3",
          "summary": "Referenz(en) aufgenommen: EUVD-2026-67094, EUVD-2026-67196, EUVD-2026-67172, EUVD-2026-67171, EUVD-2026-67170"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "OSS \u003c7.0.9",
                "product": {
                  "name": "VMware Tanzu Spring Framework OSS \u003c7.0.9",
                  "product_id": "T058449"
                }
              },
              {
                "category": "product_version",
                "name": "OSS 7.0.9",
                "product": {
                  "name": "VMware Tanzu Spring Framework OSS 7.0.9",
                  "product_id": "T058449-fixed",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:vmware_tanzu:spring_framework:oss__7.0.9"
                  }
                }
              },
              {
                "category": "product_version_range",
                "name": "Enterprise Support Only \u003c7.0.8.1",
                "product": {
                  "name": "VMware Tanzu Spring Framework Enterprise Support Only \u003c7.0.8.1",
                  "product_id": "T058454"
                }
              },
              {
                "category": "product_version",
                "name": "Enterprise Support Only 7.0.8.1",
                "product": {
                  "name": "VMware Tanzu Spring Framework Enterprise Support Only 7.0.8.1",
                  "product_id": "T058454-fixed",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:vmware_tanzu:spring_framework:enterprise_support_only__7.0.8.1"
                  }
                }
              },
              {
                "category": "product_version_range",
                "name": "Enterprise Support Only \u003c6.2.20",
                "product": {
                  "name": "VMware Tanzu Spring Framework Enterprise Support Only \u003c6.2.20",
                  "product_id": "T058455"
                }
              },
              {
                "category": "product_version",
                "name": "Enterprise Support Only 6.2.20",
                "product": {
                  "name": "VMware Tanzu Spring Framework Enterprise Support Only 6.2.20",
                  "product_id": "T058455-fixed",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:vmware_tanzu:spring_framework:enterprise_support_only__6.2.20"
                  }
                }
              },
              {
                "category": "product_version_range",
                "name": "Enterprise Support Only \u003c6.1.29",
                "product": {
                  "name": "VMware Tanzu Spring Framework Enterprise Support Only \u003c6.1.29",
                  "product_id": "T058456"
                }
              },
              {
                "category": "product_version",
                "name": "Enterprise Support Only 6.1.29",
                "product": {
                  "name": "VMware Tanzu Spring Framework Enterprise Support Only 6.1.29",
                  "product_id": "T058456-fixed",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:vmware_tanzu:spring_framework:enterprise_support_only__6.1.29"
                  }
                }
              },
              {
                "category": "product_version_range",
                "name": "Enterprise Support Only \u003c6.0.31",
                "product": {
                  "name": "VMware Tanzu Spring Framework Enterprise Support Only \u003c6.0.31",
                  "product_id": "T058457"
                }
              },
              {
                "category": "product_version",
                "name": "Enterprise Support Only 6.0.31",
                "product": {
                  "name": "VMware Tanzu Spring Framework Enterprise Support Only 6.0.31",
                  "product_id": "T058457-fixed",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:vmware_tanzu:spring_framework:enterprise_support_only__6.0.31"
                  }
                }
              },
              {
                "category": "product_version_range",
                "name": "Enterprise Support Only \u003c5.3.50",
                "product": {
                  "name": "VMware Tanzu Spring Framework Enterprise Support Only \u003c5.3.50",
                  "product_id": "T058458"
                }
              },
              {
                "category": "product_version",
                "name": "Enterprise Support Only 5.3.50",
                "product": {
                  "name": "VMware Tanzu Spring Framework Enterprise Support Only 5.3.50",
                  "product_id": "T058458-fixed",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:vmware_tanzu:spring_framework:enterprise_support_only__5.3.50"
                  }
                }
              },
              {
                "category": "product_version_range",
                "name": "Enterprise Support Only \u003c5.2.26",
                "product": {
                  "name": "VMware Tanzu Spring Framework Enterprise Support Only \u003c5.2.26",
                  "product_id": "T058459"
                }
              },
              {
                "category": "product_version",
                "name": "Enterprise Support Only 5.2.26",
                "product": {
                  "name": "VMware Tanzu Spring Framework Enterprise Support Only 5.2.26",
                  "product_id": "T058459-fixed",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:vmware_tanzu:spring_framework:enterprise_support_only__5.2.26"
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "Spring Framework"
          }
        ],
        "category": "vendor",
        "name": "VMware Tanzu"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-47883",
      "product_status": {
        "known_affected": [
          "T058459",
          "T058458",
          "T058449",
          "T058455",
          "T058454",
          "T058457",
          "T058456"
        ]
      },
      "release_date": "2026-08-20T22:00:00.000+00:00",
      "title": "CVE-2026-47883"
    },
    {
      "cve": "CVE-2026-47884",
      "product_status": {
        "known_affected": [
          "T058459",
          "T058458",
          "T058449",
          "T058455",
          "T058454",
          "T058457",
          "T058456"
        ]
      },
      "release_date": "2026-08-20T22:00:00.000+00:00",
      "title": "CVE-2026-47884"
    },
    {
      "cve": "CVE-2026-47885",
      "product_status": {
        "known_affected": [
          "T058459",
          "T058458",
          "T058449",
          "T058455",
          "T058454",
          "T058457",
          "T058456"
        ]
      },
      "release_date": "2026-08-20T22:00:00.000+00:00",
      "title": "CVE-2026-47885"
    },
    {
      "cve": "CVE-2026-47886",
      "product_status": {
        "known_affected": [
          "T058459",
          "T058458",
          "T058449",
          "T058455",
          "T058454",
          "T058457",
          "T058456"
        ]
      },
      "release_date": "2026-08-20T22:00:00.000+00:00",
      "title": "CVE-2026-47886"
    },
    {
      "cve": "CVE-2026-47887",
      "product_status": {
        "known_affected": [
          "T058459",
          "T058458",
          "T058449",
          "T058455",
          "T058454",
          "T058457",
          "T058456"
        ]
      },
      "release_date": "2026-08-20T22:00:00.000+00:00",
      "title": "CVE-2026-47887"
    },
    {
      "cve": "CVE-2026-47888",
      "product_status": {
        "known_affected": [
          "T058459",
          "T058458",
          "T058449",
          "T058455",
          "T058454",
          "T058457",
          "T058456"
        ]
      },
      "release_date": "2026-08-20T22:00:00.000+00:00",
      "title": "CVE-2026-47888"
    },
    {
      "cve": "CVE-2026-47889",
      "product_status": {
        "known_affected": [
          "T058459",
          "T058458",
          "T058449",
          "T058455",
          "T058454",
          "T058457",
          "T058456"
        ]
      },
      "release_date": "2026-08-20T22:00:00.000+00:00",
      "title": "CVE-2026-47889"
    },
    {
      "cve": "CVE-2026-47890",
      "product_status": {
        "known_affected": [
          "T058459",
          "T058458",
          "T058449",
          "T058455",
          "T058454",
          "T058457",
          "T058456"
        ]
      },
      "release_date": "2026-08-20T22:00:00.000+00:00",
      "title": "CVE-2026-47890"
    },
    {
      "cve": "CVE-2026-47891",
      "product_status": {
        "known_affected": [
          "T058459",
          "T058458",
          "T058449",
          "T058455",
          "T058454",
          "T058457",
          "T058456"
        ]
      },
      "release_date": "2026-08-20T22:00:00.000+00:00",
      "title": "CVE-2026-47891"
    },
    {
      "cve": "CVE-2026-47892",
      "product_status": {
        "known_affected": [
          "T058459",
          "T058458",
          "T058449",
          "T058455",
          "T058454",
          "T058457",
          "T058456"
        ]
      },
      "release_date": "2026-08-20T22:00:00.000+00:00",
      "title": "CVE-2026-47892"
    },
    {
      "cve": "CVE-2026-47893",
      "product_status": {
        "known_affected": [
          "T058459",
          "T058458",
          "T058449",
          "T058455",
          "T058454",
          "T058457",
          "T058456"
        ]
      },
      "release_date": "2026-08-20T22:00:00.000+00:00",
      "title": "CVE-2026-47893"
    },
    {
      "cve": "CVE-2026-59280",
      "product_status": {
        "known_affected": [
          "T058459",
          "T058458",
          "T058449",
          "T058455",
          "T058454",
          "T058457",
          "T058456"
        ]
      },
      "release_date": "2026-08-20T22:00:00.000+00:00",
      "title": "CVE-2026-59280"
    },
    {
      "cve": "CVE-2026-59281",
      "product_status": {
        "known_affected": [
          "T058459",
          "T058458",
          "T058449",
          "T058455",
          "T058454",
          "T058457",
          "T058456"
        ]
      },
      "release_date": "2026-08-20T22:00:00.000+00:00",
      "title": "CVE-2026-59281"
    },
    {
      "cve": "CVE-2026-59282",
      "product_status": {
        "known_affected": [
          "T058459",
          "T058458",
          "T058449",
          "T058455",
          "T058454",
          "T058457",
          "T058456"
        ]
      },
      "release_date": "2026-08-20T22:00:00.000+00:00",
      "title": "CVE-2026-59282"
    },
    {
      "cve": "CVE-2026-59283",
      "product_status": {
        "known_affected": [
          "T058459",
          "T058458",
          "T058449",
          "T058455",
          "T058454",
          "T058457",
          "T058456"
        ]
      },
      "release_date": "2026-08-20T22:00:00.000+00:00",
      "title": "CVE-2026-59283"
    },
    {
      "cve": "CVE-2026-59314",
      "product_status": {
        "known_affected": [
          "T058459",
          "T058458",
          "T058449",
          "T058455",
          "T058454",
          "T058457",
          "T058456"
        ]
      },
      "release_date": "2026-08-20T22:00:00.000+00:00",
      "title": "CVE-2026-59314"
    }
  ]
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…