CVE-2018-11039
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.
Spring Framework (versiones 5.0.x anteriores a la 5.0.7, versiones 4.3.x anteriores a la 4.3.18 y versiones anteriores sin soporte) permite que las aplicaciones web cambien el método de petición HTTP a cualquier método HTTP (incluyendo TRACE) utilizando HiddenHttpMethodFilter en Spring MVC. Si una aplicación tiene una vulnerabilidad Cross-Site Scripting (XSS) preexistente, un usuario (o atacante) malicioso puede emplear este filtro para escalar a un ataque XST (Cross Site Tracing).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-14 CVE Reserved
- 2018-06-25 CVE Published
- 2024-08-09 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/107984 | Broken Link | |
https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://pivotal.io/security/cve-2018-11039 | 2022-06-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vmware Search vendor "Vmware" | Spring Framework Search vendor "Vmware" for product "Spring Framework" | < 4.3.18 Search vendor "Vmware" for product "Spring Framework" and version " < 4.3.18" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Spring Framework Search vendor "Vmware" for product "Spring Framework" | >= 5.0.0 < 5.0.7 Search vendor "Vmware" for product "Spring Framework" and version " >= 5.0.0 < 5.0.7" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Agile Plm Search vendor "Oracle" for product "Agile Plm" | 9.3.3 Search vendor "Oracle" for product "Agile Plm" and version "9.3.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Agile Plm Search vendor "Oracle" for product "Agile Plm" | 9.3.4 Search vendor "Oracle" for product "Agile Plm" and version "9.3.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Agile Plm Search vendor "Oracle" for product "Agile Plm" | 9.3.5 Search vendor "Oracle" for product "Agile Plm" and version "9.3.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Agile Plm Search vendor "Oracle" for product "Agile Plm" | 9.3.6 Search vendor "Oracle" for product "Agile Plm" and version "9.3.6" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 12.5.0.3 Search vendor "Oracle" for product "Application Testing Suite" and version "12.5.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 13.1.0.1 Search vendor "Oracle" for product "Application Testing Suite" and version "13.1.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 13.2.0.1 Search vendor "Oracle" for product "Application Testing Suite" and version "13.2.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 13.3.0.1 Search vendor "Oracle" for product "Application Testing Suite" and version "13.3.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Diameter Signaling Router Search vendor "Oracle" for product "Communications Diameter Signaling Router" | < 8.3 Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version " < 8.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Network Integrity Search vendor "Oracle" for product "Communications Network Integrity" | >= 7.3.2 <= 7.3.6 Search vendor "Oracle" for product "Communications Network Integrity" and version " >= 7.3.2 <= 7.3.6" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Online Mediation Controller Search vendor "Oracle" for product "Communications Online Mediation Controller" | 6.1 Search vendor "Oracle" for product "Communications Online Mediation Controller" and version "6.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Performance Intelligence Center Search vendor "Oracle" for product "Communications Performance Intelligence Center" | < 10.2.1 Search vendor "Oracle" for product "Communications Performance Intelligence Center" and version " < 10.2.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Services Gatekeeper Search vendor "Oracle" for product "Communications Services Gatekeeper" | < 6.1.0.4.0 Search vendor "Oracle" for product "Communications Services Gatekeeper" and version " < 6.1.0.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.3.2 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.3.4 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.3.5 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.4.0 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Endeca Information Discovery Integrator Search vendor "Oracle" for product "Endeca Information Discovery Integrator" | 3.1.0 Search vendor "Oracle" for product "Endeca Information Discovery Integrator" and version "3.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Endeca Information Discovery Integrator Search vendor "Oracle" for product "Endeca Information Discovery Integrator" | 3.2.0 Search vendor "Oracle" for product "Endeca Information Discovery Integrator" and version "3.2.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Base Platform Search vendor "Oracle" for product "Enterprise Manager Base Platform" | 12.1.0.5.0 Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "12.1.0.5.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Base Platform Search vendor "Oracle" for product "Enterprise Manager Base Platform" | 13.2.0.0.0 Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "13.2.0.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Base Platform Search vendor "Oracle" for product "Enterprise Manager Base Platform" | 13.3.0.0.0 Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "13.3.0.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager For Mysql Database Search vendor "Oracle" for product "Enterprise Manager For Mysql Database" | 13.2 Search vendor "Oracle" for product "Enterprise Manager For Mysql Database" and version "13.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Ops Center Search vendor "Oracle" for product "Enterprise Manager Ops Center" | 12.3.3 Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.3.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Health Sciences Information Manager Search vendor "Oracle" for product "Health Sciences Information Manager" | 3.0 Search vendor "Oracle" for product "Health Sciences Information Manager" and version "3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Healthcare Master Person Index Search vendor "Oracle" for product "Healthcare Master Person Index" | 3.0 Search vendor "Oracle" for product "Healthcare Master Person Index" and version "3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Healthcare Master Person Index Search vendor "Oracle" for product "Healthcare Master Person Index" | 4.0 Search vendor "Oracle" for product "Healthcare Master Person Index" and version "4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Hospitality Guest Access Search vendor "Oracle" for product "Hospitality Guest Access" | 4.2.0 Search vendor "Oracle" for product "Hospitality Guest Access" and version "4.2.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Hospitality Guest Access Search vendor "Oracle" for product "Hospitality Guest Access" | 4.2.1 Search vendor "Oracle" for product "Hospitality Guest Access" and version "4.2.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Calculation Engine Search vendor "Oracle" for product "Insurance Calculation Engine" | >= 11.0.0 <= 11.3.1 Search vendor "Oracle" for product "Insurance Calculation Engine" and version " >= 11.0.0 <= 11.3.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Calculation Engine Search vendor "Oracle" for product "Insurance Calculation Engine" | 10.2 Search vendor "Oracle" for product "Insurance Calculation Engine" and version "10.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 10.0 Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 10.2 Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Micros Lucas Search vendor "Oracle" for product "Micros Lucas" | 2.9.5 Search vendor "Oracle" for product "Micros Lucas" and version "2.9.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Enterprise Monitor Search vendor "Oracle" for product "Mysql Enterprise Monitor" | <= 3.4.9.4237 Search vendor "Oracle" for product "Mysql Enterprise Monitor" and version " <= 3.4.9.4237" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Enterprise Monitor Search vendor "Oracle" for product "Mysql Enterprise Monitor" | >= 4.0.0 <= 4.0.6.5281 Search vendor "Oracle" for product "Mysql Enterprise Monitor" and version " >= 4.0.0 <= 4.0.6.5281" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Enterprise Monitor Search vendor "Oracle" for product "Mysql Enterprise Monitor" | >= 8.0.0 <= 8.0.2.8191 Search vendor "Oracle" for product "Mysql Enterprise Monitor" and version " >= 8.0.0 <= 8.0.2.8191" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera P6 Enterprise Project Portfolio Management Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" | 18.8 Search vendor "Oracle" for product "Primavera P6 Enterprise Project Portfolio Management" and version "18.8" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Advanced Inventory Planning Search vendor "Oracle" for product "Retail Advanced Inventory Planning" | 15.0 Search vendor "Oracle" for product "Retail Advanced Inventory Planning" and version "15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Assortment Planning Search vendor "Oracle" for product "Retail Assortment Planning" | 14.1 Search vendor "Oracle" for product "Retail Assortment Planning" and version "14.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Assortment Planning Search vendor "Oracle" for product "Retail Assortment Planning" | 15.0 Search vendor "Oracle" for product "Retail Assortment Planning" and version "15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Assortment Planning Search vendor "Oracle" for product "Retail Assortment Planning" | 16.0 Search vendor "Oracle" for product "Retail Assortment Planning" and version "16.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Clearance Optimization Engine Search vendor "Oracle" for product "Retail Clearance Optimization Engine" | 14.0.5 Search vendor "Oracle" for product "Retail Clearance Optimization Engine" and version "14.0.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Customer Insights Search vendor "Oracle" for product "Retail Customer Insights" | 15.0 Search vendor "Oracle" for product "Retail Customer Insights" and version "15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Customer Insights Search vendor "Oracle" for product "Retail Customer Insights" | 16.0 Search vendor "Oracle" for product "Retail Customer Insights" and version "16.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 13.2 Search vendor "Oracle" for product "Retail Financial Integration" and version "13.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 14.0 Search vendor "Oracle" for product "Retail Financial Integration" and version "14.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 14.1 Search vendor "Oracle" for product "Retail Financial Integration" and version "14.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 15.0 Search vendor "Oracle" for product "Retail Financial Integration" and version "15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 16.0 Search vendor "Oracle" for product "Retail Financial Integration" and version "16.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 14.1.2 Search vendor "Oracle" for product "Retail Integration Bus" and version "14.1.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Markdown Optimization Search vendor "Oracle" for product "Retail Markdown Optimization" | 13.4.4 Search vendor "Oracle" for product "Retail Markdown Optimization" and version "13.4.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 14.0.3.26 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "14.0.3.26" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 14.1.3.37 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "14.1.3.37" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 15.0.3..100 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "15.0.3..100" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 16.0 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "16.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 7.1 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "7.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Utilities Network Management System Search vendor "Oracle" for product "Utilities Network Management System" | 1.12.0.3 Search vendor "Oracle" for product "Utilities Network Management System" and version "1.12.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 10.3.6.0.0 Search vendor "Oracle" for product "Weblogic Server" and version "10.3.6.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 12.1.3.0.0 Search vendor "Oracle" for product "Weblogic Server" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 12.2.1.3.0 Search vendor "Oracle" for product "Weblogic Server" and version "12.2.1.3.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|