TROYANOSYVIRUS
Retour aux CVEs

CVE-2018-1273

CRITICALCISA KEV
9.8

Description

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

Details CVE

Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie4/11/2018
Derniere modification10/28/2025
Sourcekev
Observations honeypot0

CISA KEV

FournisseurVMware Tanzu
ProduitSpring Data Commons
Nom vulnerabiliteVMware Tanzu Spring Data Commons Property Binder Vulnerability
Date ajout KEV2022-03-25
Date limite remediation2022-04-15
Utilise dans ransomwareKnown

Produits affectes

apache:igniteoracle:financial_services_crime_and_compliance_management_studiopivotal_software:spring_data_commonspivotal_software:spring_data_rest

Faiblesses (CWE)

CWE-94

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.