HIGH · 7.5

CVE-2018-11040

Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through ...

Vulnerability Description

Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
VmwareSpring Framework< 4.3.18
OracleAgile Product Lifecycle Management9.3.3
OracleApplication Testing Suite12.5.0.3
OracleCommunications Network Integrity>= 7.3.2, <= 7.3.6
OracleCommunications Online Mediation Controller6.1
OracleCommunications Services Gatekeeper< 6.1.0.4.0
OracleCommunications Unified Inventory Management7.3.2
OracleEndeca Information Discovery Integrator3.1.0
OracleEnterprise Manager13.2
OracleEnterprise Manager Ops Center12.3.3
OracleFlexcube Private Banking2.0.0.0
OracleHealthcare Master Person Index3.0
OracleHospitality Guest Access4.2.0
OracleInsurance Calculation Engine>= 11.0.0, <= 11.3.1
OracleInsurance Rules Palette10.0
OracleMicros Lucas2.9.5
OracleMysql Enterprise Monitor<= 3.4.9.4237
OracleProduct Lifecycle Management9.3.6
OracleRetail Advanced Inventory Planning15.0
OracleRetail Clearance Optimization Engine14.0.5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-11040?

CVE-2018-11040 is a vulnerability with a CVSS score of 7.5 (HIGH). Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through ...

How severe is CVE-2018-11040?

CVE-2018-11040 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-11040?

Check the references section above for vendor advisories and patch information. Affected products include: Vmware Spring Framework, Oracle Agile Product Lifecycle Management, Oracle Application Testing Suite, Oracle Communications Network Integrity, Oracle Communications Online Mediation Controller.