CVE-2018-1258

Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
dellCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
pivotal_softwarespring_security
*
vmwarespring_framework
5.0.5
oracleagile_plm
9.3.3
oracleagile_plm
9.3.4
oracleagile_plm
9.3.5
oracleagile_plm
9.3.6
oracleapplication_testing_suite
10.1
oracleapplication_testing_suite
12.5.0.3
oracleapplication_testing_suite
13.1.0.1
oracleapplication_testing_suite
13.2.0.1
oracleapplication_testing_suite
13.3.0.1
oraclebig_data_discovery
1.6.0
oraclecommunications_converged_application_server
𝑥
< 7.0.0.1
oraclecommunications_diameter_signaling_router
𝑥
< 8.3
oraclecommunications_network_integrity
7.3.2 ≤
𝑥
≤ 7.3.6
oraclecommunications_performance_intelligence_center
𝑥
< 10.2.1
oraclecommunications_services_gatekeeper
𝑥
< 6.1.0.4.0
oracleendeca_information_discovery_integrator
3.1.0
oracleendeca_information_discovery_integrator
3.2.0
oracleenterprise_manager_for_mysql_database
13.2
oracleenterprise_manager_ops_center
12.2.2
oracleenterprise_manager_ops_center
12.3.3
oracleenterprise_repository
11.1.1.7.0
oracleenterprise_repository
12.1.3.0.0
oraclegoldengate_for_big_data
12.2.0.1
oraclegoldengate_for_big_data
12.3.1.1
oraclegoldengate_for_big_data
12.3.2.1
oraclehealth_sciences_information_manager
3.0
oraclehealthcare_master_person_index
3.0
oraclehealthcare_master_person_index
4.0
oraclehospitality_guest_access
4.2.0
oraclehospitality_guest_access
4.2.1
oracleinsurance_calculation_engine
10.1.1
oracleinsurance_calculation_engine
10.2
oracleinsurance_calculation_engine
10.2.1
oracleinsurance_policy_administration
10.0
oracleinsurance_policy_administration
10.1
oracleinsurance_policy_administration
10.2
oracleinsurance_policy_administration
11.0
oracleinsurance_rules_palette
10.0
oracleinsurance_rules_palette
10.1
oracleinsurance_rules_palette
10.2
oracleinsurance_rules_palette
11.0
oracleinsurance_rules_palette
11.1
oraclemicros_lucas
2.9.5
oraclemysql_enterprise_monitor
𝑥
≤ 8.0.2.8191
oraclepeoplesoft_enterprise_fin_install
9.2
oracleretail_assortment_planning
14.1
oracleretail_assortment_planning
15.0
oracleretail_assortment_planning
16.0
oracleretail_back_office
14.0
oracleretail_back_office
14.1
oracleretail_central_office
14.0
oracleretail_central_office
14.1
oracleretail_customer_insights
15.0
oracleretail_customer_insights
16.0
oracleretail_financial_integration
13.2
oracleretail_financial_integration
14.0
oracleretail_financial_integration
14.1
oracleretail_financial_integration
15.0
oracleretail_financial_integration
16.0
oracleretail_integration_bus
14.1.2
oracleretail_point-of-service
14.0
oracleretail_point-of-service
14.1
oracleretail_returns_management
14.0
oracleretail_returns_management
14.1
oracleretail_xstore_point_of_service
17.0
oracleservice_architecture_leveraging_tuxedo
12.1.3.0.0
oracleservice_architecture_leveraging_tuxedo
12.2.2.0.0
oracletape_library_acsls
8.4
oracleweblogic_server
10.3.6.0
oracleweblogic_server
12.1.3.0
oracleweblogic_server
12.2.1.2
oracleweblogic_server
12.2.1.3
netapponcommand_insight
-
netapponcommand_unified_manager
7.3 ≤
netapponcommand_unified_manager
9.4 ≤
netapponcommand_workflow_automation
-
netappsnapcenter
-
netappstorage_automation_store
-
redhatfuse
7.3.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libspring-security-2.0-java
disco
dne
cosmic
dne
bionic
dne
artful
dne
xenial
dne
trusty
dne
References