CVE-2018-1258
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
Affected (81)
Products: Pivotal Software: Spring Security · Vmware: Spring Framework · Oracle: Agile Plm, Application Testing Suite, Big Data Discovery, Communications Converged Application Server, Communications Diameter Signaling Router, Communications Network Integrity, Communications Performance Intelligence Center, Communications Services Gatekeeper, Endeca Information Discovery Integrator, Enterprise Manager For Mysql Database, Enterprise Manager Ops Center, Enterprise Repository, Goldengate For Big Data, Health Sciences Information Manager, Healthcare Master Person Index, Hospitality Guest Access, Insurance Calculation Engine, Insurance Policy Administration, Insurance Rules Palette, Micros Lucas, Mysql Enterprise Monitor, Peoplesoft Enterprise Fin Install, Retail Assortment Planning, Retail Back Office, Retail Central Office, Retail Customer Insights, Retail Financial Integration, Retail Integration Bus, Retail Point Of Service, Retail Returns Management, Retail Xstore Point Of Service, Service Architecture Leveraging Tuxedo, Tape Library Acsls, Weblogic Server · +2 more
Show all products
Pivotal Software: Spring Security · Vmware: Spring Framework · Oracle: Agile Plm, Application Testing Suite, Big Data Discovery, Communications Converged Application Server, Communications Diameter Signaling Router, Communications Network Integrity, Communications Performance Intelligence Center, Communications Services Gatekeeper, Endeca Information Discovery Integrator, Enterprise Manager For Mysql Database, Enterprise Manager Ops Center, Enterprise Repository, Goldengate For Big Data, Health Sciences Information Manager, Healthcare Master Person Index, Hospitality Guest Access, Insurance Calculation Engine, Insurance Policy Administration, Insurance Rules Palette, Micros Lucas, Mysql Enterprise Monitor, Peoplesoft Enterprise Fin Install, Retail Assortment Planning, Retail Back Office, Retail Central Office, Retail Customer Insights, Retail Financial Integration, Retail Integration Bus, Retail Point Of Service, Retail Returns Management, Retail Xstore Point Of Service, Service Architecture Leveraging Tuxedo, Tape Library Acsls, Weblogic Server · Netapp: Oncommand Insight, Oncommand Unified Manager, Oncommand Workflow Automation, Snapcenter, Storage Automation Store · Redhat: Fuse
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Version 5.0.5 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.3.3 | |
| Version 10.1 | |
| Version 1.6.0 | |
| Before 7.0.0.1 | |
| Before 8.3 | |
| From 7.3.2 to 7.3.6 | |
| Before 10.2.1 | |
| Before 6.1.0.4.0 | |
| Version 3.1.0 | |
| Version 13.2 | |
| Version 12.2.2 | |
| Version 11.1.1.7.0 | |
| Version 12.2.0.1 | |
| Version 3.0 | |
| Version 3.0 | |
| Version 4.2.0 | |
| Version 10.1.1 | |
| Version 10.0 | |
| Version 10.0 | |
| Version 2.9.5 | |
| Up to 8.0.2.8191 | |
| Version 9.2 | |
| Version 14.1 | |
| Version 14.0 | |
| Version 14.0 | |
| Version 15.0 | |
| Version 13.2 | |
| Version 14.1.2 | |
| Version 14.0 | |
| Version 14.0 | |
| Version 17.0 | |
| Version 12.1.3.0.0 | |
| Version 8.4 | |
| Version 10.3.6.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| From 9.4 | |
| All versions | |
| All versions | |
| All versions |
References (32)
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
Third Party AdvisoryVDB Entry
Source: security_alert@emc.com
Third Party AdvisoryVDB Entry
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
Third Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.