WebLogic Download of Code Without Integrity Check Vulnerability - CVE-2020-5398
In Spring Framework versions 5.2.x prior to 5.2.3 versions 5.1.x prior to 5.1.13 and versions 5.0.x prior to 5.0.16 an application is vulnerable to a reflected file download (RFD) attack when it sets a quotContent-Dispositionquot header in the response where the filename attribute is derived from user supplied input.