CRITICAL · 9.8

CVE-2018-1275

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOM...

Vulnerability Description

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
VmwareSpring Framework>= 4.3.0, < 4.3.16
OracleApplication Testing Suite12.5.0.3
OracleBig Data Discovery1.6.0
OracleCommunications Converged Application Server< 7.0.0.1
OracleCommunications Diameter Signaling Router< 8.3
OracleCommunications Performance Intelligence Center< 10.2.1
OracleCommunications Services Gatekeeper< 6.1.0.4.0
OracleGoldengate For Big Data12.2.0.1
OracleHealth Sciences Information Manager3.0
OracleHealthcare Master Person Index3.0
OracleInsurance Calculation Engine10.1.1
OracleInsurance Rules Palette10.0
OraclePrimavera Gateway15.2
OracleRetail Customer Insights15.0
OracleRetail Open Commerce Platform5.3.0
OracleRetail Order Broker5.1
OracleRetail Predictive Application Server14.0
OracleService Architecture Leveraging Tuxedo12.1.3.0.0
OracleTape Library Acsls8.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-1275?

CVE-2018-1275 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOM...

How severe is CVE-2018-1275?

CVE-2018-1275 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2018-1275?

Check the references section above for vendor advisories and patch information. Affected products include: Vmware Spring Framework, Oracle Application Testing Suite, Oracle Big Data Discovery, Oracle Communications Converged Application Server, Oracle Communications Diameter Signaling Router.