CVE-2012-1833

VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass intended access restrictions and modify arbitrary object properties via a crafted request parameter to an application.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
VendorProductVersion
springsourcegrails
𝑥
≤ 1.3.7
springsourcegrails
1.1.0
springsourcegrails
1.1.1
springsourcegrails
1.1.2
springsourcegrails
1.2.0
springsourcegrails
1.2.1
springsourcegrails
1.2.2
springsourcegrails
1.3.0
springsourcegrails
1.3.1
springsourcegrails
1.3.2
springsourcegrails
1.3.3
springsourcegrails
1.3.4
springsourcegrails
1.3.5
springsourcegrails
1.3.6
springsourcegrails
2.0
springsourcegrails
2.0.1
𝑥
= Vulnerable software versions
Common Weakness Enumeration