CVE-2018-1273

Scores

EPSS

0.943High94.3%
0%20%40%60%80%100%

Percentile: 94.3%

CVSS

9.8Critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Description

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data’s projection-based request payload binding hat can lead to a remote code execution attack.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-138CWE-94

Related Vulnerabilities

Exploits

Exploit ID: CVE-2018-1273

Source: cisa

URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Vulnerable Software (4)

Type: Configuration

Vendor: apache

Product: ignite

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:apache:ignite:*:*:*:*:*:*:*:*",
      "versionEndIncluding": "2.5.0",
      "versionStartIncluding": "1.0.1",
      "vulnerable": true
    },
    ...

Source: nvd

Type: Configuration

Vendor: oracle

Product: financial_services_crime_and_compliance_management_studio

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.2.0:*:*:*:*:*:*:*",
      "vulnerable": true
    },
    {
      "cpe23uri":...

Source: nvd

Type: Configuration

Vendor: pivotal_software

Product: spring_data_commons

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:pivotal_software:spring_data_commons:*:*:*:*:*:*:*:*",
      "versionEndIncluding": "1.12.10",
      "vulnerable": true
    },
    {
      "cpe23u...

Source: nvd

Type: Configuration

Vendor: pivotal_software

Product: spring_data_rest

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:pivotal_software:spring_data_rest:*:*:*:*:*:*:*:*",
      "versionEndIncluding": "2.5.10",
      "vulnerable": true
    },
    {
      "cpe23uri":...

Source: nvd