CVE-2018-1275

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
dellCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
vmwarespring_framework
4.3.0 ≤
𝑥
< 4.3.16
vmwarespring_framework
5.0.0 ≤
𝑥
< 5.0.5
oracleapplication_testing_suite
12.5.0.3
oracleapplication_testing_suite
13.1.0.1
oracleapplication_testing_suite
13.2.0.1
oracleapplication_testing_suite
13.3.0.1
oraclebig_data_discovery
1.6.0
oraclecommunications_converged_application_server
𝑥
< 7.0.0.1
oraclecommunications_diameter_signaling_router
𝑥
< 8.3
oraclecommunications_performance_intelligence_center
𝑥
< 10.2.1
oraclecommunications_services_gatekeeper
𝑥
< 6.1.0.4.0
oraclegoldengate_for_big_data
12.2.0.1
oraclegoldengate_for_big_data
12.3.1.1
oraclegoldengate_for_big_data
12.3.2.1
oraclehealth_sciences_information_manager
3.0
oraclehealthcare_master_person_index
3.0
oraclehealthcare_master_person_index
4.0
oracleinsurance_calculation_engine
10.1.1
oracleinsurance_calculation_engine
10.2
oracleinsurance_calculation_engine
10.2.1
oracleinsurance_rules_palette
10.0
oracleinsurance_rules_palette
10.1
oracleinsurance_rules_palette
10.2
oracleinsurance_rules_palette
11.0
oracleinsurance_rules_palette
11.1
oracleprimavera_gateway
15.2
oracleprimavera_gateway
16.2
oracleprimavera_gateway
17.12
oracleretail_customer_insights
15.0
oracleretail_customer_insights
16.0
oracleretail_open_commerce_platform
5.3.0
oracleretail_open_commerce_platform
6.0.0
oracleretail_open_commerce_platform
6.0.1
oracleretail_order_broker
5.1
oracleretail_order_broker
5.2
oracleretail_order_broker
15.0
oracleretail_order_broker
16.0
oracleretail_predictive_application_server
14.0
oracleretail_predictive_application_server
14.1
oracleretail_predictive_application_server
15.0
oracleretail_predictive_application_server
16.0
oracleservice_architecture_leveraging_tuxedo
12.1.3.0.0
oracleservice_architecture_leveraging_tuxedo
12.2.2.0.0
oracletape_library_acsls
8.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libspring-java
bullseye
4.3.30-1
fixed
sid
4.3.30-2
fixed
trixie
4.3.30-2
fixed
bookworm
4.3.30-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libspring-java
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
ignored
xenial
not-affected
trusty
not-affected
References