← Back

CVE-2018-11039

nvd nist
Published: Jun 25, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

Affected (64)

Products: Vmware: Spring Framework · Oracle: Agile Plm, Application Testing Suite, Communications Diameter Signaling Router, Communications Network Integrity, Communications Online Mediation Controller, Communications Performance Intelligence Center, Communications Services Gatekeeper, Communications Unified Inventory Management, Endeca Information Discovery Integrator, Enterprise Manager Base Platform, Enterprise Manager For Mysql Database, Enterprise Manager Ops Center, Health Sciences Information Manager, Healthcare Master Person Index, Hospitality Guest Access, Insurance Calculation Engine, Insurance Rules Palette, Micros Lucas, Mysql Enterprise Monitor, Primavera P6 Enterprise Project Portfolio Management, Retail Advanced Inventory Planning, Retail Assortment Planning, Retail Clearance Optimization Engine, Retail Customer Insights, Retail Financial Integration, Retail Integration Bus, Retail Markdown Optimization, Retail Predictive Application Server, Retail Xstore Point Of Service, Utilities Network Management System, Weblogic Server · Debian: Debian Linux
1 product
Spring Framework
31 products
Agile Plm
Application Testing Suite
Communications Network Integrity
Enterprise Manager Base Platform
Enterprise Manager Ops Center
Healthcare Master Person Index
Hospitality Guest Access
Insurance Calculation Engine
Insurance Rules Palette
Micros Lucas
Mysql Enterprise Monitor
Retail Assortment Planning
Retail Customer Insights
Retail Financial Integration
Retail Integration Bus
Retail Markdown Optimization
Retail Xstore Point Of Service
Weblogic Server
1 product
Debian Linux
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
Before 4.3.18
From 5.0.0 to 5.0.7
Configuration B
61 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 9.3.3
Version 9.3.4
Version 9.3.5
Version 9.3.6
Oracle
Version 12.5.0.3
Version 13.1.0.1
Version 13.2.0.1
Version 13.3.0.1
Before 8.3
From 7.3.2 to 7.3.6
Version 6.1
Before 10.2.1
Before 6.1.0.4.0
Oracle
Version 7.3.2
Version 7.3.4
Version 7.3.5
Version 7.4.0
Oracle
Version 3.1.0
Version 3.2.0
Oracle
Version 12.1.0.5.0
Version 13.2.0.0.0
Version 13.3.0.0.0
Version 13.2
Version 12.3.3
Version 3.0
Oracle
Version 3.0
Version 4.0
Oracle
Version 4.2.0
Version 4.2.1
Oracle
From 11.0.0 to 11.3.1
Version 10.2
Oracle
Version 10.0
Version 10.2
Version 2.9.5
Oracle
Up to 3.4.9.4237
From 4.0.0 to 4.0.6.5281
From 8.0.0 to 8.0.2.8191
Version 18.8
Version 15.0
Oracle
Version 14.1
Version 15.0
Version 16.0
Version 14.0.5
Oracle
Version 15.0
Version 16.0
Oracle
Version 13.2
Version 14.0
Version 14.1
Version 15.0
Version 16.0
Version 14.1.2
Version 13.4.4
Oracle
Version 14.0.3.26
Version 14.1.3.37
Version 15.0.3..100
Version 16.0
Version 7.1
Version 1.12.0.3
Oracle
Version 10.3.6.0.0
Version 12.1.3.0.0
Version 12.2.1.3.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0

References (20)

Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
Broken LinkThird Party AdvisoryVDB Entry
Source: security_alert@emc.com
Mailing ListThird Party Advisory
Source: security_alert@emc.com
MitigationVendor Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.