CVE-2018-1275
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.
Affected (44)
Products: Vmware: Spring Framework · Oracle: Application Testing Suite, Big Data Discovery, Communications Converged Application Server, Communications Diameter Signaling Router, Communications Performance Intelligence Center, Communications Services Gatekeeper, Goldengate For Big Data, Health Sciences Information Manager, Healthcare Master Person Index, Insurance Calculation Engine, Insurance Rules Palette, Primavera Gateway, Retail Customer Insights, Retail Open Commerce Platform, Retail Order Broker, Retail Predictive Application Server, Service Architecture Leveraging Tuxedo, Tape Library Acsls
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.3.0 to 4.3.16 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.5.0.3 | |
| Version 1.6.0 | |
| Before 7.0.0.1 | |
| Before 8.3 | |
| Before 10.2.1 | |
| Before 6.1.0.4.0 | |
| Version 12.2.0.1 | |
| Version 3.0 | |
| Version 3.0 | |
| Version 10.1.1 | |
| Version 10.0 | |
| Version 15.2 | |
| Version 15.0 | |
| Version 5.3.0 | |
| Version 15.0 | |
| Version 14.0 | |
| Version 12.1.3.0.0 | |
| Version 8.4 |
Related CWEs
CWE-358
Improperly Implemented Security Check for Standard
The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
CWE-94
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
References (28)
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
Third Party AdvisoryVDB Entry
Source: security_alert@emc.com
Source: security_alert@emc.com
Source: security_alert@emc.com
Source: security_alert@emc.com
Third Party Advisory
Source: security_alert@emc.com
Third Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.