CVE-2018-11040
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests.
Spring Framework, en versiones 5.0.x anteriores a la 5.0.7 y versiones 4.3.x anteriores a la 4.3.18 y versiones anteriores sin soporte, permite que las aplicaciones web habiliten peticiones de dominio cruzado mediante JSONP (JSON with Padding) mediante AbstractJsonpResponseBodyAdvice para controladores REST y MappingJackson2JsonView para las peticiones del navegador. Ninguna de las dos está habilitada por defecto en Spring Framework o Spring Boot. Sin embargo, cuando MappingJackson2JsonView está configurado en una aplicación, el soporte para JSONP está automáticamente listo para ser empleado mediante los parámetros JSONP "jsonp" y "callback", lo que habilita peticiones de dominio cruzado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-14 CVE Reserved
- 2018-06-25 CVE Published
- 2024-08-09 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-829: Inclusion of Functionality from Untrusted Control Sphere
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://pivotal.io/security/cve-2018-11040 | 2022-06-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vmware Search vendor "Vmware" | Spring Framework Search vendor "Vmware" for product "Spring Framework" | < 4.3.18 Search vendor "Vmware" for product "Spring Framework" and version " < 4.3.18" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Spring Framework Search vendor "Vmware" for product "Spring Framework" | >= 5.0.0 < 5.0.7 Search vendor "Vmware" for product "Spring Framework" and version " >= 5.0.0 < 5.0.7" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Agile Product Lifecycle Management Search vendor "Oracle" for product "Agile Product Lifecycle Management" | 9.3.3 Search vendor "Oracle" for product "Agile Product Lifecycle Management" and version "9.3.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Agile Product Lifecycle Management Search vendor "Oracle" for product "Agile Product Lifecycle Management" | 9.3.4 Search vendor "Oracle" for product "Agile Product Lifecycle Management" and version "9.3.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Agile Product Lifecycle Management Search vendor "Oracle" for product "Agile Product Lifecycle Management" | 9.3.5 Search vendor "Oracle" for product "Agile Product Lifecycle Management" and version "9.3.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 12.5.0.3 Search vendor "Oracle" for product "Application Testing Suite" and version "12.5.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 13.1.0.1 Search vendor "Oracle" for product "Application Testing Suite" and version "13.1.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 13.2.0.1 Search vendor "Oracle" for product "Application Testing Suite" and version "13.2.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 13.3.0.1 Search vendor "Oracle" for product "Application Testing Suite" and version "13.3.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Network Integrity Search vendor "Oracle" for product "Communications Network Integrity" | >= 7.3.2 <= 7.3.6 Search vendor "Oracle" for product "Communications Network Integrity" and version " >= 7.3.2 <= 7.3.6" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Online Mediation Controller Search vendor "Oracle" for product "Communications Online Mediation Controller" | 6.1 Search vendor "Oracle" for product "Communications Online Mediation Controller" and version "6.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Services Gatekeeper Search vendor "Oracle" for product "Communications Services Gatekeeper" | < 6.1.0.4.0 Search vendor "Oracle" for product "Communications Services Gatekeeper" and version " < 6.1.0.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.3.2 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.3.4 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.3.5 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.4.0 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Endeca Information Discovery Integrator Search vendor "Oracle" for product "Endeca Information Discovery Integrator" | 3.1.0 Search vendor "Oracle" for product "Endeca Information Discovery Integrator" and version "3.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Endeca Information Discovery Integrator Search vendor "Oracle" for product "Endeca Information Discovery Integrator" | 3.2.0 Search vendor "Oracle" for product "Endeca Information Discovery Integrator" and version "3.2.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Search vendor "Oracle" for product "Enterprise Manager" | 13.2 Search vendor "Oracle" for product "Enterprise Manager" and version "13.2" | mysql |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Ops Center Search vendor "Oracle" for product "Enterprise Manager Ops Center" | 12.3.3 Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.3.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Flexcube Private Banking Search vendor "Oracle" for product "Flexcube Private Banking" | 2.0.0.0 Search vendor "Oracle" for product "Flexcube Private Banking" and version "2.0.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Flexcube Private Banking Search vendor "Oracle" for product "Flexcube Private Banking" | 2.2.0.1 Search vendor "Oracle" for product "Flexcube Private Banking" and version "2.2.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Flexcube Private Banking Search vendor "Oracle" for product "Flexcube Private Banking" | 12.0.1.0 Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.0.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Flexcube Private Banking Search vendor "Oracle" for product "Flexcube Private Banking" | 12.0.3.0 Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Flexcube Private Banking Search vendor "Oracle" for product "Flexcube Private Banking" | 12.1.0.0 Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.1.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Healthcare Master Person Index Search vendor "Oracle" for product "Healthcare Master Person Index" | 3.0 Search vendor "Oracle" for product "Healthcare Master Person Index" and version "3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Healthcare Master Person Index Search vendor "Oracle" for product "Healthcare Master Person Index" | 4.0 Search vendor "Oracle" for product "Healthcare Master Person Index" and version "4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Hospitality Guest Access Search vendor "Oracle" for product "Hospitality Guest Access" | 4.2.0 Search vendor "Oracle" for product "Hospitality Guest Access" and version "4.2.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Hospitality Guest Access Search vendor "Oracle" for product "Hospitality Guest Access" | 4.2.1 Search vendor "Oracle" for product "Hospitality Guest Access" and version "4.2.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Calculation Engine Search vendor "Oracle" for product "Insurance Calculation Engine" | >= 11.0.0 <= 11.3.1 Search vendor "Oracle" for product "Insurance Calculation Engine" and version " >= 11.0.0 <= 11.3.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 10.0 Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 10.2 Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Micros Lucas Search vendor "Oracle" for product "Micros Lucas" | 2.9.5 Search vendor "Oracle" for product "Micros Lucas" and version "2.9.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Enterprise Monitor Search vendor "Oracle" for product "Mysql Enterprise Monitor" | <= 3.4.9.4237 Search vendor "Oracle" for product "Mysql Enterprise Monitor" and version " <= 3.4.9.4237" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Enterprise Monitor Search vendor "Oracle" for product "Mysql Enterprise Monitor" | >= 3.4.10 <= 4.0.6.5281 Search vendor "Oracle" for product "Mysql Enterprise Monitor" and version " >= 3.4.10 <= 4.0.6.5281" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Enterprise Monitor Search vendor "Oracle" for product "Mysql Enterprise Monitor" | >= 4.0.7 <= 8.0.2.8191 Search vendor "Oracle" for product "Mysql Enterprise Monitor" and version " >= 4.0.7 <= 8.0.2.8191" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Product Lifecycle Management Search vendor "Oracle" for product "Product Lifecycle Management" | 9.3.6 Search vendor "Oracle" for product "Product Lifecycle Management" and version "9.3.6" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Advanced Inventory Planning Search vendor "Oracle" for product "Retail Advanced Inventory Planning" | 15.0 Search vendor "Oracle" for product "Retail Advanced Inventory Planning" and version "15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Clearance Optimization Engine Search vendor "Oracle" for product "Retail Clearance Optimization Engine" | 14.0.5 Search vendor "Oracle" for product "Retail Clearance Optimization Engine" and version "14.0.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Customer Insights Search vendor "Oracle" for product "Retail Customer Insights" | 15.0 Search vendor "Oracle" for product "Retail Customer Insights" and version "15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Customer Insights Search vendor "Oracle" for product "Retail Customer Insights" | 16.0 Search vendor "Oracle" for product "Retail Customer Insights" and version "16.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Markdown Optimization Search vendor "Oracle" for product "Retail Markdown Optimization" | 13.4.4 Search vendor "Oracle" for product "Retail Markdown Optimization" and version "13.4.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 14.0.3.26 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "14.0.3.26" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 14.1.3.37 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "14.1.3.37" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 15.0.3.100 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "15.0.3.100" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 16.0 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "16.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Service Backbone Search vendor "Oracle" for product "Retail Service Backbone" | 16.0.1 Search vendor "Oracle" for product "Retail Service Backbone" and version "16.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 7.1 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "7.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Utilities Network Management System Search vendor "Oracle" for product "Utilities Network Management System" | 1.12.0.3 Search vendor "Oracle" for product "Utilities Network Management System" and version "1.12.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 12.2.1.3.0 Search vendor "Oracle" for product "Weblogic Server" and version "12.2.1.3.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|