The vendor explicitly identifies these products as affected by this CVE.
- springframework as a component of Red Hat Decision Manager 7
- springframework as a component of Red Hat Integration Data Virtualisation Operator
- springframework as a component of Red Hat JBoss BRMS 5
- springframework as a component of Red Hat JBoss Data Grid 7
- springframework as a component of Red Hat JBoss Data Virtualization 6
- springframework as a component of Red Hat JBoss Enterprise Application Platform 6
- springframework as a component of Red Hat JBoss Fuse 6
- springframework as a component of Red Hat JBoss Fuse Service Works 6
- springframework as a component of Red Hat JBoss SOA Platform 5
- springframework as a component of Red Hat Process Automation 7
- Summary
- A flaw was found in Spring Framework. Applications that handle file uploads are vulnerable to a denial of service (DoS) attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
- Remediation
- Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings. The References section of this erratum contains a download link (you must log in to download the update).
