HIGH · 7.5

CVE-2018-1272

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux ser...

Vulnerability Description

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
VmwareSpring Framework>= 4.3.0, < 4.3.15
OracleApplication Testing Suite12.5.0.3
OracleBig Data Discovery1.6.0
OracleCommunications Converged Application Server< 7.0.0.1
OracleCommunications Diameter Signaling Router< 8.3
OracleCommunications Performance Intelligence Center< 10.2.1
OracleCommunications Services Gatekeeper< 6.1.0.4.0
OracleEnterprise Manager Ops Center12.2.2
OracleGoldengate For Big Data12.2.0.1
OracleHealth Sciences Information Manager3.0
OracleHealthcare Master Person Index3.0
OracleInsurance Calculation Engine10.1.1
OracleInsurance Rules Palette10.0
OraclePrimavera Gateway15.2
OracleRetail Back Office14.0
OracleRetail Central Office14.0
OracleRetail Customer Insights15.0
OracleRetail Integration Bus14.0.1
OracleRetail Open Commerce Platform5.3.0
OracleRetail Order Broker5.1

References

FAQ

What is CVE-2018-1272?

CVE-2018-1272 is a vulnerability with a CVSS score of 7.5 (HIGH). Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux ser...

How severe is CVE-2018-1272?

CVE-2018-1272 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-1272?

Check the references section above for vendor advisories and patch information. Affected products include: Vmware Spring Framework, Oracle Application Testing Suite, Oracle Big Data Discovery, Oracle Communications Converged Application Server, Oracle Communications Diameter Signaling Router.