MEDIUM · 5.9

CVE-2018-1271

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, image...

Vulnerability Description

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
VmwareSpring Framework>= 4.3.0, < 4.3.15
OracleApplication Testing Suite12.5.0.3
OracleBig Data Discovery1.6.0
OracleCommunications Converged Application Server< 7.0.0.1
OracleCommunications Diameter Signaling Router< 8.3
OracleCommunications Performance Intelligence Center< 10.2.1
OracleCommunications Policy Management12.5.0
OracleCommunications Services Gatekeeper< 6.1.0.4.0
OracleEnterprise Manager Ops Center12.2.2
OracleGoldengate For Big Data12.2.0.1
OracleHealth Sciences Information Manager3.0
OracleHealthcare Master Person Index3.0
OracleInsurance Calculation Engine>= 11.0.0, <= 11.3.1
OracleInsurance Rules Palette10.0
OraclePrimavera Gateway15.2
OracleRapid Planning12.1
OracleRetail Back Office14.0
OracleRetail Central Office14.0
OracleRetail Customer Insights15.0
OracleRetail Integration Bus14.0.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-1271?

CVE-2018-1271 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, image...

How severe is CVE-2018-1271?

CVE-2018-1271 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-1271?

Check the references section above for vendor advisories and patch information. Affected products include: Vmware Spring Framework, Oracle Application Testing Suite, Oracle Big Data Discovery, Oracle Communications Converged Application Server, Oracle Communications Diameter Signaling Router.