CVE-2018-1257
spring-framework: ReDoS Attack with spring-messaging
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.
Spring Framework, en versiones 5.0.x anteriores a la 5.0.6, versiones 4.3.x anteriores a la 4.3.17 y versiones antiguas no soportadas, permite que las aplicaciones expongan STOMP sobre los endpoints WebSocket con un simple broker STOP dentro de la memoria a través del módulo spring-messaging. Un usuario (o atacante) malicioso puede crear un mensaje para el broker que puede conducir a un ataque de denegación de servicio (DoS) de expresión regular.
Red Hat Fuse enables integration experts, application developers, and business users to collaborate and independently develop connected solutions. Fuse is part of an agile integration solution. Its distributed approach allows teams to deploy integrated services where required. The API-centric, container-based architecture decouples services so they can be created, extended, and deployed independently. This release of Red Hat Fuse 7.2 serves as a replacement for Red Hat Fuse 7.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Issues addressed include code execution, denial of service, deserialization, and traversal vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-06 CVE Reserved
- 2018-05-11 CVE Published
- 2024-09-16 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/104260 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2018:1809 | 2022-06-23 | |
https://access.redhat.com/errata/RHSA-2018:3768 | 2022-06-23 | |
https://pivotal.io/security/cve-2018-1257 | 2022-06-23 | |
https://access.redhat.com/security/cve/CVE-2018-1257 | 2018-12-04 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1578578 | 2018-12-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vmware Search vendor "Vmware" | Spring Framework Search vendor "Vmware" for product "Spring Framework" | < 4.3.17 Search vendor "Vmware" for product "Spring Framework" and version " < 4.3.17" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Spring Framework Search vendor "Vmware" for product "Spring Framework" | >= 5.0.0 < 5.0.6 Search vendor "Vmware" for product "Spring Framework" and version " >= 5.0.0 < 5.0.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openshift Search vendor "Redhat" for product "Openshift" | - | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Agile Product Lifecycle Management Search vendor "Oracle" for product "Agile Product Lifecycle Management" | 9.3.3 Search vendor "Oracle" for product "Agile Product Lifecycle Management" and version "9.3.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Agile Product Lifecycle Management Search vendor "Oracle" for product "Agile Product Lifecycle Management" | 9.3.4 Search vendor "Oracle" for product "Agile Product Lifecycle Management" and version "9.3.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Agile Product Lifecycle Management Search vendor "Oracle" for product "Agile Product Lifecycle Management" | 9.3.5 Search vendor "Oracle" for product "Agile Product Lifecycle Management" and version "9.3.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Agile Product Lifecycle Management Search vendor "Oracle" for product "Agile Product Lifecycle Management" | 9.3.6 Search vendor "Oracle" for product "Agile Product Lifecycle Management" and version "9.3.6" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 12.5.0.3 Search vendor "Oracle" for product "Application Testing Suite" and version "12.5.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 13.1.0.1 Search vendor "Oracle" for product "Application Testing Suite" and version "13.1.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 13.2.0.1 Search vendor "Oracle" for product "Application Testing Suite" and version "13.2.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 13.3.0.1 Search vendor "Oracle" for product "Application Testing Suite" and version "13.3.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Big Data Discovery Search vendor "Oracle" for product "Big Data Discovery" | 1.6.0 Search vendor "Oracle" for product "Big Data Discovery" and version "1.6.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Converged Application Server Search vendor "Oracle" for product "Communications Converged Application Server" | < 7.0.0.1 Search vendor "Oracle" for product "Communications Converged Application Server" and version " < 7.0.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Diameter Signaling Router Search vendor "Oracle" for product "Communications Diameter Signaling Router" | < 8.3 Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version " < 8.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Performance Intelligence Center Search vendor "Oracle" for product "Communications Performance Intelligence Center" | < 10.2.1 Search vendor "Oracle" for product "Communications Performance Intelligence Center" and version " < 10.2.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Services Gatekeeper Search vendor "Oracle" for product "Communications Services Gatekeeper" | < 6.1.0.4.0 Search vendor "Oracle" for product "Communications Services Gatekeeper" and version " < 6.1.0.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.3.2 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.3.4 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.3.5 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.4.0 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Endeca Information Discovery Integrator Search vendor "Oracle" for product "Endeca Information Discovery Integrator" | 3.1.0 Search vendor "Oracle" for product "Endeca Information Discovery Integrator" and version "3.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Endeca Information Discovery Integrator Search vendor "Oracle" for product "Endeca Information Discovery Integrator" | 3.2.0 Search vendor "Oracle" for product "Endeca Information Discovery Integrator" and version "3.2.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Base Platform Search vendor "Oracle" for product "Enterprise Manager Base Platform" | 12.1.0.5.0 Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "12.1.0.5.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Base Platform Search vendor "Oracle" for product "Enterprise Manager Base Platform" | 13.2.0.0.0 Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "13.2.0.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Base Platform Search vendor "Oracle" for product "Enterprise Manager Base Platform" | 13.3.0.0.0 Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "13.3.0.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager For Mysql Database Search vendor "Oracle" for product "Enterprise Manager For Mysql Database" | 13.2 Search vendor "Oracle" for product "Enterprise Manager For Mysql Database" and version "13.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Ops Center Search vendor "Oracle" for product "Enterprise Manager Ops Center" | 12.3.3 Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.3.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Flexcube Private Banking Search vendor "Oracle" for product "Flexcube Private Banking" | 2.0.0.0 Search vendor "Oracle" for product "Flexcube Private Banking" and version "2.0.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Flexcube Private Banking Search vendor "Oracle" for product "Flexcube Private Banking" | 2.2.0.1 Search vendor "Oracle" for product "Flexcube Private Banking" and version "2.2.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Flexcube Private Banking Search vendor "Oracle" for product "Flexcube Private Banking" | 12.0.1.0 Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.0.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Flexcube Private Banking Search vendor "Oracle" for product "Flexcube Private Banking" | 12.0.3.0 Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Flexcube Private Banking Search vendor "Oracle" for product "Flexcube Private Banking" | 12.1.0.0 Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.1.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Goldengate For Big Data Search vendor "Oracle" for product "Goldengate For Big Data" | 12.2.0.1 Search vendor "Oracle" for product "Goldengate For Big Data" and version "12.2.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Goldengate For Big Data Search vendor "Oracle" for product "Goldengate For Big Data" | 12.3.1.1 Search vendor "Oracle" for product "Goldengate For Big Data" and version "12.3.1.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Goldengate For Big Data Search vendor "Oracle" for product "Goldengate For Big Data" | 12.3.2.1 Search vendor "Oracle" for product "Goldengate For Big Data" and version "12.3.2.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Health Sciences Information Manager Search vendor "Oracle" for product "Health Sciences Information Manager" | 3.0 Search vendor "Oracle" for product "Health Sciences Information Manager" and version "3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Healthcare Master Person Index Search vendor "Oracle" for product "Healthcare Master Person Index" | 3.0 Search vendor "Oracle" for product "Healthcare Master Person Index" and version "3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Healthcare Master Person Index Search vendor "Oracle" for product "Healthcare Master Person Index" | 4.0 Search vendor "Oracle" for product "Healthcare Master Person Index" and version "4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Hospitality Guest Access Search vendor "Oracle" for product "Hospitality Guest Access" | 4.2.0 Search vendor "Oracle" for product "Hospitality Guest Access" and version "4.2.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Hospitality Guest Access Search vendor "Oracle" for product "Hospitality Guest Access" | 4.2.1 Search vendor "Oracle" for product "Hospitality Guest Access" and version "4.2.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Calculation Engine Search vendor "Oracle" for product "Insurance Calculation Engine" | 10.1.1 Search vendor "Oracle" for product "Insurance Calculation Engine" and version "10.1.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Calculation Engine Search vendor "Oracle" for product "Insurance Calculation Engine" | 10.2 Search vendor "Oracle" for product "Insurance Calculation Engine" and version "10.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Calculation Engine Search vendor "Oracle" for product "Insurance Calculation Engine" | 10.2.1 Search vendor "Oracle" for product "Insurance Calculation Engine" and version "10.2.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 10.0 Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 10.1 Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 10.2 Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 11.0 Search vendor "Oracle" for product "Insurance Rules Palette" and version "11.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 11.1 Search vendor "Oracle" for product "Insurance Rules Palette" and version "11.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Gateway Search vendor "Oracle" for product "Primavera Gateway" | 15.2 Search vendor "Oracle" for product "Primavera Gateway" and version "15.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Gateway Search vendor "Oracle" for product "Primavera Gateway" | 16.2 Search vendor "Oracle" for product "Primavera Gateway" and version "16.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Gateway Search vendor "Oracle" for product "Primavera Gateway" | 17.12 Search vendor "Oracle" for product "Primavera Gateway" and version "17.12" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Customer Insights Search vendor "Oracle" for product "Retail Customer Insights" | 15.0 Search vendor "Oracle" for product "Retail Customer Insights" and version "15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Customer Insights Search vendor "Oracle" for product "Retail Customer Insights" | 16.0 Search vendor "Oracle" for product "Retail Customer Insights" and version "16.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Open Commerce Platform Search vendor "Oracle" for product "Retail Open Commerce Platform" | 5.3.0 Search vendor "Oracle" for product "Retail Open Commerce Platform" and version "5.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Open Commerce Platform Search vendor "Oracle" for product "Retail Open Commerce Platform" | 6.0.0 Search vendor "Oracle" for product "Retail Open Commerce Platform" and version "6.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Open Commerce Platform Search vendor "Oracle" for product "Retail Open Commerce Platform" | 6.0.1 Search vendor "Oracle" for product "Retail Open Commerce Platform" and version "6.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Order Broker Search vendor "Oracle" for product "Retail Order Broker" | 5.1 Search vendor "Oracle" for product "Retail Order Broker" and version "5.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Order Broker Search vendor "Oracle" for product "Retail Order Broker" | 5.2 Search vendor "Oracle" for product "Retail Order Broker" and version "5.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Order Broker Search vendor "Oracle" for product "Retail Order Broker" | 15.0 Search vendor "Oracle" for product "Retail Order Broker" and version "15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Order Broker Search vendor "Oracle" for product "Retail Order Broker" | 16.0 Search vendor "Oracle" for product "Retail Order Broker" and version "16.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 14.0 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "14.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 14.1 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "14.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 15.0 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 16.0 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "16.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Service Architecture Leveraging Tuxedo Search vendor "Oracle" for product "Service Architecture Leveraging Tuxedo" | 12.1.3.0.0 Search vendor "Oracle" for product "Service Architecture Leveraging Tuxedo" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Service Architecture Leveraging Tuxedo Search vendor "Oracle" for product "Service Architecture Leveraging Tuxedo" | 12.2.2.0.0 Search vendor "Oracle" for product "Service Architecture Leveraging Tuxedo" and version "12.2.2.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Tape Library Acsls Search vendor "Oracle" for product "Tape Library Acsls" | 8.4 Search vendor "Oracle" for product "Tape Library Acsls" and version "8.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Utilities Network Management System Search vendor "Oracle" for product "Utilities Network Management System" | 1.12.0.3 Search vendor "Oracle" for product "Utilities Network Management System" and version "1.12.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 10.3.6.0.0 Search vendor "Oracle" for product "Weblogic Server" and version "10.3.6.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 12.1.3.0.0 Search vendor "Oracle" for product "Weblogic Server" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 12.2.1.3.0 Search vendor "Oracle" for product "Weblogic Server" and version "12.2.1.3.0" | - |
Affected
|