Home / CVE DB / CVE-2016-1000027
Standard
Vulnerability Identifier

CVE-2016-1000027

2020-01-02
Severity Assessment
9.8
CRITICAL
CVSS v3.x Score
Clinical Analysis (Description)

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

Vector Sequencing

Attack Parameters

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Impact Consequences

Technical Impact

Unchanged
Scope
High
Confidentiality
High
Integrity
High
Availability
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2 Score (Legacy)
7.5

For backward compatibility

EPSS Probability
60.42%

Percentile: 98.3%

Weakness Classification

CWE-CWE-502

Affected Population

Affected Configurations

Total: 203 detected entries

Software List Scrollable
vm
spring_framework
Vendor: vmware • v3.2.0
vm
spring_framework
Vendor: vmware • v5.3.33
vm
spring_framework
Vendor: vmware • v4.1.4
vm
spring_framework
Vendor: vmware • v4.1.0
vm
spring_framework
Vendor: vmware • v5.0.17
vm
spring_framework
Vendor: vmware • v5.3.31
vm
spring_framework
Vendor: vmware • v5.3.1
vm
spring_framework
Vendor: vmware • v5.0.11
vm
spring_framework
Vendor: vmware • v5.1.10
vm
spring_framework
Vendor: vmware • v4.2.5
vm
spring_framework
Vendor: vmware • v5.3.4
vm
spring_framework
Vendor: vmware • v4.3.26
vm
spring_framework
Vendor: vmware • v5.2.23
vm
spring_framework
Vendor: vmware • v5.1.7
vm
spring_framework
Vendor: vmware • v3.2.11
vm
spring_framework
Vendor: vmware • v5.2.13
vm
spring_framework
Vendor: vmware • v3.0.3
vm
spring_framework
Vendor: vmware • v5.3.28
vm
spring_framework
Vendor: vmware • v5.3.37
vm
spring_framework
Vendor: vmware • v5.3.18
vm
spring_framework
Vendor: vmware • v4.3.20
vm
spring_framework
Vendor: vmware • v3.1.3
vm
spring_framework
Vendor: vmware • v4.3.28
vm
spring_framework
Vendor: vmware • v4.3.16
vm
spring_framework
Vendor: vmware • v4.1.9
vm
spring_framework
Vendor: vmware • v5.2.16
vm
spring_framework
Vendor: vmware • v5.1.9
vm
spring_framework
Vendor: vmware • v5.2.17
vm
spring_framework
Vendor: vmware • v5.3.8
vm
spring_framework
Vendor: vmware • v5.3.19
vm
spring_framework
Vendor: vmware • v5.2.25
vm
spring_framework
Vendor: vmware • v4.0.8
vm
spring_framework
Vendor: vmware • v5.0.2
vm
spring_framework
Vendor: vmware • v5.2.14
vm
spring_framework
Vendor: vmware • v4.3.2
vm
spring_framework
Vendor: vmware • v5.0.10
vm
spring_framework
Vendor: vmware • v4.3.0
vm
spring_framework
Vendor: vmware • v4.3.1
vm
spring_framework
Vendor: vmware • v5.3.38
vm
spring_framework
Vendor: vmware • v4.1.1
vm
spring_framework
Vendor: vmware • v4.2.0
vm
spring_framework
Vendor: vmware • v4.0.5
vm
spring_framework
Vendor: vmware • v4.3.21
vm
spring_framework
Vendor: vmware • v3.2.13
vm
spring_framework
Vendor: vmware • v4.0.2
vm
spring_framework
Vendor: vmware • v5.2.9
vm
spring_framework
Vendor: vmware • v3.0.2
vm
spring_framework
Vendor: vmware • v4.1.6
vm
spring_framework
Vendor: vmware • v5.2.2
vm
spring_framework
Vendor: vmware • v4.3.4
vm
spring_framework
Vendor: vmware • v5.2.21
vm
spring_framework
Vendor: vmware • v4.1.2
vm
spring_framework
Vendor: vmware • v5.3.29
vm
spring_framework
Vendor: vmware • v5.3.14
vm
spring_framework
Vendor: vmware • v4.3.5
vm
spring_framework
Vendor: vmware • v4.2.9
vm
spring_framework
Vendor: vmware • v5.2.3
vm
spring_framework
Vendor: vmware • v3.2.4
vm
spring_framework
Vendor: vmware • v5.2.19
vm
spring_framework
Vendor: vmware • v5.1.20
vm
spring_framework
Vendor: vmware • v5.1.14
vm
spring_framework
Vendor: vmware • v3.2.17
vm
spring_framework
Vendor: vmware • v5.3.27
vm
spring_framework
Vendor: vmware • v5.3.13
vm
spring_framework
Vendor: vmware • v5.3.24
vm
spring_framework
Vendor: vmware • v5.2.0
vm
spring_framework
Vendor: vmware • v5.2.20
vm
spring_framework
Vendor: vmware • v5.0.3
vm
spring_framework
Vendor: vmware • v5.3.17
vm
spring_framework
Vendor: vmware • v4.3.18
vm
spring_framework
Vendor: vmware • v5.2.22
vm
spring_framework
Vendor: vmware • v5.3.30
vm
spring_framework
Vendor: vmware • v5.3.10
vm
spring_framework
Vendor: vmware • v5.1.11
vm
spring_framework
Vendor: vmware • v5.1.6
vm
spring_framework
Vendor: vmware • v4.3.30
vm
spring_framework
Vendor: vmware • v4.3.7
vm
spring_framework
Vendor: vmware • v4.1.8
vm
spring_framework
Vendor: vmware • v3.2.15
vm
spring_framework
Vendor: vmware • v5.1.15
vm
spring_framework
Vendor: vmware • v3.2.12
vm
spring_framework
Vendor: vmware • v5.0.12
vm
spring_framework
Vendor: vmware • v5.0.13
vm
spring_framework
Vendor: vmware • v5.3.0
vm
spring_framework
Vendor: vmware • v5.1.16
vm
spring_framework
Vendor: vmware • v5.1.19
vm
spring_framework
Vendor: vmware • v5.2.11
vm
spring_framework
Vendor: vmware • v5.3.26
vm
spring_framework
Vendor: vmware • v5.1.13
vm
spring_framework
Vendor: vmware • v5.3.23
vm
spring_framework
Vendor: vmware • v3.0.6
vm
spring_framework
Vendor: vmware • v5.0.8
vm
spring_framework
Vendor: vmware • v5.0.1
vm
spring_framework
Vendor: vmware • v5.3.40
vm
spring_framework
Vendor: vmware • v4.3.29
vm
spring_framework
Vendor: vmware • v3.2.2
vm
spring_framework
Vendor: vmware • v4.3.11
vm
spring_framework
Vendor: vmware • v5.2.7
vm
spring_framework
Vendor: vmware • v4.2.8
vm
spring_framework
Vendor: vmware • v5.3.7
vm
spring_framework
Vendor: vmware • v3.2.1
vm
spring_framework
Vendor: vmware • v5.3.21
vm
spring_framework
Vendor: vmware • v5.2.6
vm
spring_framework
Vendor: vmware • v4.0.9
vm
spring_framework
Vendor: vmware • v3.2.3
vm
spring_framework
Vendor: vmware • v3.2.16
vm
spring_framework
Vendor: vmware • v5.3.12
vm
spring_framework
Vendor: vmware • v4.3.6
vm
spring_framework
Vendor: vmware • v5.2.5
vm
spring_framework
Vendor: vmware • v3.0.0
vm
spring_framework
Vendor: vmware • v4.3.3
vm
spring_framework
Vendor: vmware • v5.2.1
vm
spring_framework
Vendor: vmware • v5.0.6
vm
spring_framework
Vendor: vmware • v3.1.1
vm
spring_framework
Vendor: vmware • v5.3.41
vm
spring_framework
Vendor: vmware • v4.3.13
vm
spring_framework
Vendor: vmware • v3.1.2
vm
spring_framework
Vendor: vmware • v4.0.3
vm
spring_framework
Vendor: vmware • v4.0.0
vm
spring_framework
Vendor: vmware • v4.2.7
vm
spring_framework
Vendor: vmware • v4.2.1
vm
spring_framework
Vendor: vmware • v5.3.11
vm
spring_framework
Vendor: vmware • v5.3.36
vm
spring_framework
Vendor: vmware • v5.0.18
vm
spring_framework
Vendor: vmware • v5.1.12
vm
spring_framework
Vendor: vmware • v5.2.8
vm
spring_framework
Vendor: vmware • v5.2.4
vm
spring_framework
Vendor: vmware • v5.1.4
vm
spring_framework
Vendor: vmware • v5.0.0
vm
spring_framework
Vendor: vmware • v4.3.24
vm
spring_framework
Vendor: vmware • v4.3.27
vm
spring_framework
Vendor: vmware • v3.0.4
vm
spring_framework
Vendor: vmware • v5.3.20
vm
spring_framework
Vendor: vmware • v5.0.5
vm
spring_framework
Vendor: vmware • v4.3.17
vm
spring_framework
Vendor: vmware • v5.0.7
vm
spring_framework
Vendor: vmware • v5.3.35
vm
spring_framework
Vendor: vmware • v5.0.19
vm
spring_framework
Vendor: vmware • v4.2.2
vm
spring_framework
Vendor: vmware • v3.2.5
vm
spring_framework
Vendor: vmware • v5.1.0
vm
spring_framework
Vendor: vmware • v4.3.15
vm
spring_framework
Vendor: vmware • v5.1.2
vm
spring_framework
Vendor: vmware • v5.2.18
vm
spring_framework
Vendor: vmware • v4.3.10
vm
spring_framework
Vendor: vmware • v5.2.12
vm
spring_framework
Vendor: vmware • v4.3.9
vm
spring_framework
Vendor: vmware • v4.3.14
vm
spring_framework
Vendor: vmware • v5.0.20
vm
spring_framework
Vendor: vmware • v5.3.6
vm
spring_framework
Vendor: vmware • v4.1.7
vm
spring_framework
Vendor: vmware • v5.0.9
vm
spring_framework
Vendor: vmware • v4.3.19
vm
spring_framework
Vendor: vmware • v5.1.5
vm
spring_framework
Vendor: vmware • v3.2.10
vm
spring_framework
Vendor: vmware • v4.1.3
vm
spring_framework
Vendor: vmware • v5.0.15
vm
spring_framework
Vendor: vmware • v5.0.4
vm
spring_framework
Vendor: vmware • v3.2.6
vm
spring_framework
Vendor: vmware • v5.3.25
vm
spring_framework
Vendor: vmware • v5.1.8
vm
spring_framework
Vendor: vmware • v4.3.8
vm
spring_framework
Vendor: vmware • v5.2.15
vm
spring_framework
Vendor: vmware • v4.2.3
vm
spring_framework
Vendor: vmware • v5.3.3
vm
spring_framework
Vendor: vmware • v4.0.7
vm
spring_framework
Vendor: vmware • v5.3.2
vm
spring_framework
Vendor: vmware • v5.1.3
vm
spring_framework
Vendor: vmware • v5.1.1
vm
spring_framework
Vendor: vmware • v5.2.10
vm
spring_framework
Vendor: vmware • v3.2.14
vm
spring_framework
Vendor: vmware • v3.0.5
vm
spring_framework
Vendor: vmware • v5.3.32
vm
spring_framework
Vendor: vmware • v5.3.5
vm
spring_framework
Vendor: vmware • v4.2.4
vm
spring_framework
Vendor: vmware • v5.1.18
vm
spring_framework
Vendor: vmware • v5.2.24
vm
spring_framework
Vendor: vmware • v5.3.15
vm
spring_framework
Vendor: vmware • v4.3.12
vm
spring_framework
Vendor: vmware • v4.0.6
vm
spring_framework
Vendor: vmware • v3.1.4
vm
spring_framework
Vendor: vmware • v5.3.39
vm
spring_framework
Vendor: vmware • v4.0.4
vm
spring_framework
Vendor: vmware • v4.3.22
vm
spring_framework
Vendor: vmware • v5.3.34
vm
spring_framework
Vendor: vmware • v3.2.7
vm
spring_framework
Vendor: vmware • v5.0.16
vm
spring_framework
Vendor: vmware • v5.3.9
vm
spring_framework
Vendor: vmware • v4.2.6
vm
spring_framework
Vendor: vmware • v5.3.16
vm
spring_framework
Vendor: vmware • v4.3.25
vm
spring_framework
Vendor: vmware • v3.1.0
vm
spring_framework
Vendor: vmware • v3.0.7
vm
spring_framework
Vendor: vmware • v5.0.14
vm
spring_framework
Vendor: vmware • v4.1.5
vm
spring_framework
Vendor: vmware • v4.3.23
vm
spring_framework
Vendor: vmware • v3.0.1
vm
spring_framework
Vendor: vmware • v3.2.9
vm
spring_framework
Vendor: vmware • v5.1.17
vm
spring_framework
Vendor: vmware • v3.2.18
vm
spring_framework
Vendor: vmware • v3.2.8
vm
spring_framework
Vendor: vmware • v4.0.1
vm
spring_framework
Vendor: vmware • v5.3.22
Timeline

Time Line

PUBLICATION
02 Jan 2020
MODIFICATION
21 Nov 2024
FIRST PATCH
15 Apr 2025
Impact Statistics

Key Metrics

CVSS Score
9.8
CRITICAL
Products
203
Affected
Patches
2
Available
Remediation Protocol

Recommended Solution

No automatic solution found. Check vendor references.
Recommended Actions for Administrators

Immediate Action Plan

1. Inventory

Identify all affected systems in your infrastructure.

2. Assessment

Assess exposure and criticality for your organization.

3. Mitigation

Apply patches or available workarounds.

4. Verification

Test and confirm effectiveness of applied measures.

⚠️ MAXIMUM PRIORITY - Immediate action required