2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2018-1275" ,
"sourceIdentifier" : "security_alert@emc.com" ,
"published" : "2018-04-11T13:29:00.353" ,
2023-11-07 21:03:21 +00:00
"lastModified" : "2023-11-07T02:55:54.387" ,
"vulnStatus" : "Modified" ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework."
} ,
{
"lang" : "es" ,
"value" : "Spring Framework, en versiones anteriores a las comprendidas entre la 5.0 y la 5.0.5, versiones 4.3 anteriores a la 4.3.16 y versiones antiguas no soportadas, permite que las aplicaciones expongan STOMP sobre los endpoints WebSocket con un simple broker STOP dentro de la memoria a trav\u00e9s del m\u00f3dulo spring-messaging. Un usuario (o atacante) malicioso puede crear un mensaje para el broker que puede conducir a un ataque de ejecuci\u00f3n remota de c\u00f3digo. Este CVE hace referencia a una soluci\u00f3n parcial de CVE-2018-1270 en la rama 4.3.x de Spring Framework."
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P" ,
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
"availabilityImpact" : "PARTIAL" ,
"baseScore" : 7.5
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 10.0 ,
"impactScore" : 6.4 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
2023-11-07 21:03:21 +00:00
"source" : "c550e75a-17ff-4988-97f0-544cde3820fe" ,
2023-04-24 12:24:31 +02:00
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-94"
}
]
} ,
{
"source" : "nvd@nist.gov" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-358"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "4.3.0" ,
"versionEndExcluding" : "4.3.16" ,
"matchCriteriaId" : "F4C1A62A-E019-4649-AB74-DB249D1B03EF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "5.0.0" ,
"versionEndExcluding" : "5.0.5" ,
"matchCriteriaId" : "8D2CC334-AFF8-41D4-9FBD-88C8FF9DA406"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:application_testing_suite:12.5.0.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "17EA8B91-7634-4636-B647-1049BA7CA088"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:application_testing_suite:13.1.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5B4DF46F-DBCC-41F2-A260-F83A14838F23"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:application_testing_suite:13.2.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "10F17843-32EA-4C31-B65C-F424447BEF7B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A125E817-F974-4509-872C-B71933F42AD1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:big_data_discovery:1.6.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "00280604-1DC1-4974-BF73-216C5D76FFA3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:communications_converged_application_server:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "7.0.0.1" ,
"matchCriteriaId" : "EC361999-AAD8-4CB3-B00E-E3990C3529B4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "8.3" ,
"matchCriteriaId" : "CF5A0F0D-313D-4F5C-AD6D-8C118D5CD8D8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:communications_performance_intelligence_center:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "10.2.1" ,
"matchCriteriaId" : "468931C8-C76A-4E47-BF00-185D85F719C5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:communications_services_gatekeeper:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "6.1.0.4.0" ,
"matchCriteriaId" : "97C1FA4C-5163-420C-A01A-EA36F1039BBB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:goldengate_for_big_data:12.2.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1C4A89F2-713D-4A36-9D28-22748D30E0FD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:goldengate_for_big_data:12.3.1.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CDFABB2C-2FA2-4F83-985B-7FCEAF274418"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:goldengate_for_big_data:12.3.2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6A609003-8687-40B4-8AC3-06A1534ADE30"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:health_sciences_information_manager:3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9027528A-4FE7-4E3C-B2DF-CCCED22128F5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:healthcare_master_person_index:3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2A699D02-296B-411E-9658-5893240605D6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:healthcare_master_person_index:4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7036576C-2B1F-413D-B154-2DBF9BFDE7E3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:insurance_calculation_engine:10.1.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CEE4B2F0-1AAB-4A1F-AE86-A568D43891B3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:insurance_calculation_engine:10.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "641D134E-6C51-4DB8-8554-F6B5222EF479"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:insurance_calculation_engine:10.2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C79B50C2-27C2-4A9C-ACEE-B70015283F58"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:insurance_rules_palette:10.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DB6321F8-7A0A-4DB8-9889-3527023C652A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:insurance_rules_palette:10.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "25F8E604-8180-4728-AD2D-7FF034E3E65A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:insurance_rules_palette:10.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "02867DC7-E669-43C0-ACC4-E1CAA8B9994C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:insurance_rules_palette:11.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FBAFA631-C92B-4FF7-8E65-07C67789EBCD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:insurance_rules_palette:11.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9652104A-119D-4327-A937-8BED23C23861"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:primavera_gateway:15.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6CBFA960-D242-43ED-8D4C-A60F01B70740"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:primavera_gateway:16.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0513B305-97EF-4609-A82E-D0CDFF9925BA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:primavera_gateway:17.12:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "61A7F6E0-A4A4-4FC3-90CB-156933CB3B9A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:retail_customer_insights:15.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AD4AB77A-E829-4603-AF6A-97B9CD0D687F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:retail_customer_insights:16.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6DE15D64-6F49-4F43-8079-0C7827384C86"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:retail_open_commerce_platform:5.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "07630491-0624-4C5C-A858-C5D3CDCD1B68"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:retail_open_commerce_platform:6.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EC9CA11F-F718-43E5-ADB9-6C348C75E37A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:retail_open_commerce_platform:6.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9FBAAD32-1E9D-47F1-9F47-76FEA47EF54F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:retail_order_broker:5.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EAA4DF85-9225-4422-BF10-D7DAE7DCE007"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:retail_order_broker:5.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "77C2A2A4-285B-40A1-B9AD-42219D742DD4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:retail_order_broker:15.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EE8CF045-09BB-4069-BCEC-496D5AE3B780"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:retail_order_broker:16.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "38E74E68-7F19-4EF3-AC00-3C249EAAA39E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:retail_predictive_application_server:14.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BD3C8E59-B07D-4C5E-B467-2FA6C1DFDA5B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:retail_predictive_application_server:14.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F6DA82ED-20FF-4E6D-ACA0-C65F51F4F5C0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:retail_predictive_application_server:15.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6FFEA075-11EB-4E99-92A1-8B2883C64CC0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:retail_predictive_application_server:16.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "21973CDD-D16E-4321-9F8E-67F4264D7C21"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:service_architecture_leveraging_tuxedo:12.1.3.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "909A7F73-0164-471B-8EBD-1F70072E9809"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:service_architecture_leveraging_tuxedo:12.2.2.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2CE08DC9-5153-48D6-B23C-68A632FF8FF5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:oracle:tape_library_acsls:8.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "70D4467D-6968-4557-AF61-AFD42B2B48D3"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html" ,
"source" : "security_alert@emc.com" ,
"tags" : [
"Patch" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html" ,
"source" : "security_alert@emc.com" ,
"tags" : [
"Patch" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://www.securityfocus.com/bid/103771" ,
"source" : "security_alert@emc.com" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://www.securitytracker.com/id/1041301" ,
"source" : "security_alert@emc.com" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2018:1320" ,
"source" : "security_alert@emc.com" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2018:2939" ,
"source" : "security_alert@emc.com" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
2023-11-07 21:03:21 +00:00
"url" : "https://lists.apache.org/thread.html/4ed49b103f64a0cecb38064f26cbf1389afc12124653da2d35166dbe%40%3Cissues.activemq.apache.org%3E" ,
"source" : "security_alert@emc.com"
2023-04-24 12:24:31 +02:00
} ,
{
2023-11-07 21:03:21 +00:00
"url" : "https://lists.apache.org/thread.html/ab825fcade0b49becfa30235b3d54f4a51bb74ea96b6c9adb5d1378c%40%3Cissues.activemq.apache.org%3E" ,
"source" : "security_alert@emc.com"
2023-04-24 12:24:31 +02:00
} ,
{
2023-11-07 21:03:21 +00:00
"url" : "https://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369%40%3Cissues.activemq.apache.org%3E" ,
"source" : "security_alert@emc.com"
2023-04-24 12:24:31 +02:00
} ,
{
"url" : "https://pivotal.io/security/cve-2018-1275" ,
"source" : "security_alert@emc.com" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "https://www.oracle.com/security-alerts/cpujul2020.html" ,
"source" : "security_alert@emc.com" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://www.oracle.com/security-alerts/cpuoct2021.html" ,
"source" : "security_alert@emc.com" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html" ,
"source" : "security_alert@emc.com" ,
"tags" : [
"Patch" ,
"Third Party Advisory"
]
} ,
{
"url" : "https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html" ,
"source" : "security_alert@emc.com" ,
"tags" : [
"Patch" ,
"Third Party Advisory"
]
}
]
}