CVE-2018-1271

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
dellCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
vmwarespring_framework
4.3.0 ≤
𝑥
< 4.3.15
vmwarespring_framework
5.0.0 ≤
𝑥
< 5.0.5
oracleapplication_testing_suite
12.5.0.3
oracleapplication_testing_suite
13.1.0.1
oracleapplication_testing_suite
13.2.0.1
oracleapplication_testing_suite
13.3.0.1
oraclebig_data_discovery
1.6.0
oraclecommunications_converged_application_server
𝑥
< 7.0.0.1
oraclecommunications_diameter_signaling_router
𝑥
< 8.3
oraclecommunications_performance_intelligence_center
𝑥
< 10.2.1
oraclecommunications_policy_management
12.5.0
oraclecommunications_services_gatekeeper
𝑥
< 6.1.0.4.0
oracleenterprise_manager_ops_center
12.2.2
oracleenterprise_manager_ops_center
12.3.3
oraclegoldengate_for_big_data
12.2.0.1
oraclegoldengate_for_big_data
12.3.1.1
oraclegoldengate_for_big_data
12.3.2.1
oraclehealth_sciences_information_manager
3.0
oraclehealthcare_master_person_index
3.0
oraclehealthcare_master_person_index
4.0
oracleinsurance_calculation_engine
11.0.0 ≤
𝑥
≤ 11.3.1
oracleinsurance_calculation_engine
10.1.1
oracleinsurance_calculation_engine
10.2
oracleinsurance_calculation_engine
10.2.1
oracleinsurance_rules_palette
10.0
oracleinsurance_rules_palette
10.1
oracleinsurance_rules_palette
10.2
oracleinsurance_rules_palette
11.0
oracleinsurance_rules_palette
11.1
oracleprimavera_gateway
15.2
oracleprimavera_gateway
16.2
oracleprimavera_gateway
17.12
oraclerapid_planning
12.1
oraclerapid_planning
12.2
oracleretail_back_office
14.0
oracleretail_back_office
14.1
oracleretail_central_office
14.0
oracleretail_central_office
14.1
oracleretail_customer_insights
15.0
oracleretail_customer_insights
16.0
oracleretail_integration_bus
14.0.1
oracleretail_integration_bus
14.0.2
oracleretail_integration_bus
14.0.3
oracleretail_integration_bus
14.0.4
oracleretail_integration_bus
14.1.1
oracleretail_integration_bus
14.1.2
oracleretail_integration_bus
14.1.3
oracleretail_integration_bus
15.0.0.1
oracleretail_integration_bus
15.0.1
oracleretail_integration_bus
15.0.2
oracleretail_integration_bus
16.0
oracleretail_integration_bus
16.0.1
oracleretail_integration_bus
16.0.2
oracleretail_open_commerce_platform
5.3.0
oracleretail_open_commerce_platform
6.0.0
oracleretail_open_commerce_platform
6.0.1
oracleretail_order_broker
5.1
oracleretail_order_broker
5.2
oracleretail_order_broker
15.0
oracleretail_order_broker
16.0
oracleretail_point-of-sale
14.0
oracleretail_point-of-sale
14.1
oracleretail_predictive_application_server
14.0
oracleretail_predictive_application_server
14.1
oracleretail_predictive_application_server
15.0
oracleretail_predictive_application_server
16.0
oracleretail_returns_management
14.0
oracleretail_returns_management
14.1
oracleretail_xstore_point_of_service
7.1
oracleservice_architecture_leveraging_tuxedo
12.1.3.0.0
oracleservice_architecture_leveraging_tuxedo
12.2.2.0.0
oracletape_library_acsls
8.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libspring-java
bullseye
4.3.30-1
fixed
sid
4.3.30-2
fixed
trixie
4.3.30-2
fixed
bookworm
4.3.30-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libspring-java
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
ignored
xenial
not-affected
trusty
not-affected