# CVE-2020-5408

## Summary

- **CVE ID:** CVE-2020-5408
- **Severity:** UNKNOWN
- **CVSS Score:** 0.02
- **CWE:** CWE-329
- **Published:** May 14, 2020
- **Last Modified:** Mar 14, 2026

## Description

Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to the data that has been encrypted using such an encryptor may be able to derive the unencrypted values using a dictionary attack.

## Affected Products

- Spring by VMware — Spring Security (4.2)
- Spring by VMware — Spring Security (5.0)
- Spring by VMware — Spring Security (5.1)
- Spring by VMware — Spring Security (5.2)
- Spring by VMware — Spring Security (5.3)

## References

- [CNA](https://www.oracle.com/security-alerts/cpuoct2020.html)
- [CNA](https://tanzu.vmware.com/security/cve-2020-5408)
- [CNA](https://www.oracle.com/security-alerts/cpujan2021.html)
- [CNA](https://www.oracle.com/security-alerts/cpuApr2021.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.47%
- **EPSS Percentile:** 64.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._