MEDIUM🇵🇱 Wersja polska

CVE-2026-47861

CVSS 6.3v3.1pub. 2026-08-27upd. 2026-09-02

An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
  • VMware Spring Integration

    APP
    Vmware
    < 5.5.226.4.0 – 6.4.13 (excl.)6.5.0 – 6.5.11 (excl.)7.0.0 – 7.0.5.1 (excl.)7.1.0 – 7.1.0.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-5413CRITICAL9.8PL ✓same product

RCE przez deserializację Kryo w Spring Integration Framework

CVE-2019-3772CRITICAL9.8PL ✓same product

XXE Injection w Spring Integration (moduły XML i WS)

CVE-2026-59324HIGH8.2same product

When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payl...

CVE-2026-59307HIGH8.0same product

An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protect...

CVE-2026-40987HIGH7.1same product

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (ou...