CVE-2010-3700
Last modified
CVE-2010-3700 is a vulnerability of currently unknown severity. VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.. EPSS estimates a 1.67% chance of exploitation in the next 30 days.
Description
VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Acegisecurity | Acegi-Security | 1.0.0 |
| Acegisecurity | Acegi-Security | 1.0.1 |
| Acegisecurity | Acegi-Security | 1.0.2 |
| Acegisecurity | Acegi-Security | 1.0.3 |
| Acegisecurity | Acegi-Security | 1.0.4 |
| Acegisecurity | Acegi-Security | 1.0.5 |
| Acegisecurity | Acegi-Security | 1.0.6 |
| Acegisecurity | Acegi-Security | 1.0.7 |
| Vmware | Springsource Spring Security | 2.0.0 |
| Vmware | Springsource Spring Security | 2.0.1 |
| Vmware | Springsource Spring Security | 2.0.2 |
| Vmware | Springsource Spring Security | 2.0.3 |
| Vmware | Springsource Spring Security | 2.0.4 |
| Vmware | Springsource Spring Security | 2.0.5 |
| Vmware | Springsource Spring Security | 3.0.0 |
| Vmware | Springsource Spring Security | 3.0.1 |
| Vmware | Springsource Spring Security | 3.0.2 |
| Vmware | Springsource Spring Security | 3.0.3 |
| Ibm | Websphere Application Server | 6.1 |
| Ibm | Websphere Application Server | 7.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3700?
How severe is CVE-2010-3700?
How do I fix CVE-2010-3700?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-3694Cross-site request forgery (CSRF) vulnerability in the Horde…
- CVE-2010-3695Cross-site scripting (XSS) vulnerability in fetchmailprefs.p…
- CVE-2010-3696The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.…
- CVE-2010-3697The wait_for_child_to_die function in main/event.c in FreeRA…
- CVE-2010-3698The KVM implementation in the Linux kernel before 2.6.36 doe…
- CVE-2010-3699The backend driver in Xen 3.x allows guest OS users to cause…
- CVE-2010-3701lib/MessageStoreImpl.cpp in Red Hat Enterprise MRG before 1.…
- CVE-2010-3702The Gfx::getPos function in the PDF parser in xpdf before 3.…
- CVE-2010-3703The PostScriptFunction::PostScriptFunction function in poppl…
- CVE-2010-3704The FoFiType1::parse function in fofi/FoFiType1.cc in the PD…
- CVE-2010-3705The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in t…
- CVE-2010-3706plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.…
Are you affected by CVE-2010-3700?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
