CVE-2018-1270
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
Affected (70)
Products: Vmware: Spring Framework · Oracle: Application Testing Suite, Big Data Discovery, Communications Converged Application Server, Communications Diameter Signaling Router, Communications Performance Intelligence Center, Communications Services Gatekeeper, Enterprise Manager Ops Center, Goldengate For Big Data, Health Sciences Information Manager, Healthcare Master Person Index, Insurance Calculation Engine, Insurance Rules Palette, Primavera Gateway, Retail Back Office, Retail Central Office, Retail Customer Insights, Retail Integration Bus, Retail Open Commerce Platform, Retail Order Broker, Retail Point Of Sale, Retail Predictive Application Server, Retail Returns Management, Retail Xstore Point Of Service, Service Architecture Leveraging Tuxedo, Tape Library Acsls · Redhat: Fuse · +1 more
Show all products
Vmware: Spring Framework · Oracle: Application Testing Suite, Big Data Discovery, Communications Converged Application Server, Communications Diameter Signaling Router, Communications Performance Intelligence Center, Communications Services Gatekeeper, Enterprise Manager Ops Center, Goldengate For Big Data, Health Sciences Information Manager, Healthcare Master Person Index, Insurance Calculation Engine, Insurance Rules Palette, Primavera Gateway, Retail Back Office, Retail Central Office, Retail Customer Insights, Retail Integration Bus, Retail Open Commerce Platform, Retail Order Broker, Retail Point Of Sale, Retail Predictive Application Server, Retail Returns Management, Retail Xstore Point Of Service, Service Architecture Leveraging Tuxedo, Tape Library Acsls · Redhat: Fuse · Debian: Debian Linux
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.3.16 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.5.0.3 | |
| Version 1.6.0 | |
| Before 7.0.0.1 | |
| Before 8.3 | |
| Before 10.2.1 | |
| Before 6.1.0.4.0 | |
| Version 12.2.2 | |
| Version 12.2.0.1 | |
| Version 3.0 | |
| Version 3.0 | |
| Version 10.1.1 | |
| Version 10.0 | |
| Version 15.2 | |
| Version 14.0 | |
| Version 14.0 | |
| Version 15.0 | |
| Version 14.0.1 | |
| Version 5.3.0 | |
| Version 15.0 | |
| Version 14.0 | |
| Version 14.0 | |
| Version 14.0 | |
| Version 7.1 | |
| Version 12.1.3.0.0 | |
| Version 8.4 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.0 |
Related CWEs
CWE-358
Improperly Implemented Security Check for Standard
The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
CWE-94
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
References (32)
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
Source: security_alert@emc.com
Source: security_alert@emc.com
Source: security_alert@emc.com
Source: security_alert@emc.com
Source: security_alert@emc.com
Mailing ListThird Party Advisory
Source: security_alert@emc.com
Broken LinkThird Party AdvisoryVDB Entry
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.