MEDIUM · 5.9

CVE-2018-11039

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including ...

Vulnerability Description

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
VmwareSpring Framework< 4.3.18
OracleAgile Plm9.3.3
OracleApplication Testing Suite12.5.0.3
OracleCommunications Diameter Signaling Router< 8.3
OracleCommunications Network Integrity>= 7.3.2, <= 7.3.6
OracleCommunications Online Mediation Controller6.1
OracleCommunications Performance Intelligence Center< 10.2.1
OracleCommunications Services Gatekeeper< 6.1.0.4.0
OracleCommunications Unified Inventory Management7.3.2
OracleEndeca Information Discovery Integrator3.1.0
OracleEnterprise Manager Base Platform12.1.0.5.0
OracleEnterprise Manager For Mysql Database13.2
OracleEnterprise Manager Ops Center12.3.3
OracleHealth Sciences Information Manager3.0
OracleHealthcare Master Person Index3.0
OracleHospitality Guest Access4.2.0
OracleInsurance Calculation Engine>= 11.0.0, <= 11.3.1
OracleInsurance Rules Palette10.0
OracleMicros Lucas2.9.5
OracleMysql Enterprise Monitor<= 3.4.9.4237

References

FAQ

What is CVE-2018-11039?

CVE-2018-11039 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including ...

How severe is CVE-2018-11039?

CVE-2018-11039 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-11039?

Check the references section above for vendor advisories and patch information. Affected products include: Vmware Spring Framework, Oracle Agile Plm, Oracle Application Testing Suite, Oracle Communications Diameter Signaling Router, Oracle Communications Network Integrity.