CVE-2012-1833

EUVD-2012-1843
VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass intended access restrictions and modify arbitrary object properties via a crafted request parameter to an application.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
Affected Products (NVD)
VendorProductVersion
springsourcegrails
𝑥
≤ 1.3.7
springsourcegrails
1.1.0
springsourcegrails
1.1.1
springsourcegrails
1.1.2
springsourcegrails
1.2.0
springsourcegrails
1.2.1
springsourcegrails
1.2.2
springsourcegrails
1.3.0
springsourcegrails
1.3.1
springsourcegrails
1.3.2
springsourcegrails
1.3.3
springsourcegrails
1.3.4
springsourcegrails
1.3.5
springsourcegrails
1.3.6
springsourcegrails
2.0
springsourcegrails
2.0.1
𝑥
= Vulnerable software versions
Common Weakness Enumeration