// For flags

CVE-2018-1257

spring-framework: ReDoS Attack with spring-messaging

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.

Spring Framework, en versiones 5.0.x anteriores a la 5.0.6, versiones 4.3.x anteriores a la 4.3.17 y versiones antiguas no soportadas, permite que las aplicaciones expongan STOMP sobre los endpoints WebSocket con un simple broker STOP dentro de la memoria a través del módulo spring-messaging. Un usuario (o atacante) malicioso puede crear un mensaje para el broker que puede conducir a un ataque de denegación de servicio (DoS) de expresión regular.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
Low
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-12-06 CVE Reserved
  • 2018-05-11 CVE Published
  • 2024-07-04 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Vmware
Search vendor "Vmware"
Spring Framework
Search vendor "Vmware" for product "Spring Framework"
< 4.3.17
Search vendor "Vmware" for product "Spring Framework" and version " < 4.3.17"
-
Affected
Vmware
Search vendor "Vmware"
Spring Framework
Search vendor "Vmware" for product "Spring Framework"
>= 5.0.0 < 5.0.6
Search vendor "Vmware" for product "Spring Framework" and version " >= 5.0.0 < 5.0.6"
-
Affected
Redhat
Search vendor "Redhat"
Openshift
Search vendor "Redhat" for product "Openshift"
--
Affected
Oracle
Search vendor "Oracle"
Agile Product Lifecycle Management
Search vendor "Oracle" for product "Agile Product Lifecycle Management"
9.3.3
Search vendor "Oracle" for product "Agile Product Lifecycle Management" and version "9.3.3"
-
Affected
Oracle
Search vendor "Oracle"
Agile Product Lifecycle Management
Search vendor "Oracle" for product "Agile Product Lifecycle Management"
9.3.4
Search vendor "Oracle" for product "Agile Product Lifecycle Management" and version "9.3.4"
-
Affected
Oracle
Search vendor "Oracle"
Agile Product Lifecycle Management
Search vendor "Oracle" for product "Agile Product Lifecycle Management"
9.3.5
Search vendor "Oracle" for product "Agile Product Lifecycle Management" and version "9.3.5"
-
Affected
Oracle
Search vendor "Oracle"
Agile Product Lifecycle Management
Search vendor "Oracle" for product "Agile Product Lifecycle Management"
9.3.6
Search vendor "Oracle" for product "Agile Product Lifecycle Management" and version "9.3.6"
-
Affected
Oracle
Search vendor "Oracle"
Application Testing Suite
Search vendor "Oracle" for product "Application Testing Suite"
12.5.0.3
Search vendor "Oracle" for product "Application Testing Suite" and version "12.5.0.3"
-
Affected
Oracle
Search vendor "Oracle"
Application Testing Suite
Search vendor "Oracle" for product "Application Testing Suite"
13.1.0.1
Search vendor "Oracle" for product "Application Testing Suite" and version "13.1.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Application Testing Suite
Search vendor "Oracle" for product "Application Testing Suite"
13.2.0.1
Search vendor "Oracle" for product "Application Testing Suite" and version "13.2.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Application Testing Suite
Search vendor "Oracle" for product "Application Testing Suite"
13.3.0.1
Search vendor "Oracle" for product "Application Testing Suite" and version "13.3.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Big Data Discovery
Search vendor "Oracle" for product "Big Data Discovery"
1.6.0
Search vendor "Oracle" for product "Big Data Discovery" and version "1.6.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Converged Application Server
Search vendor "Oracle" for product "Communications Converged Application Server"
< 7.0.0.1
Search vendor "Oracle" for product "Communications Converged Application Server" and version " < 7.0.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Diameter Signaling Router
Search vendor "Oracle" for product "Communications Diameter Signaling Router"
< 8.3
Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version " < 8.3"
-
Affected
Oracle
Search vendor "Oracle"
Communications Performance Intelligence Center
Search vendor "Oracle" for product "Communications Performance Intelligence Center"
< 10.2.1
Search vendor "Oracle" for product "Communications Performance Intelligence Center" and version " < 10.2.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Services Gatekeeper
Search vendor "Oracle" for product "Communications Services Gatekeeper"
< 6.1.0.4.0
Search vendor "Oracle" for product "Communications Services Gatekeeper" and version " < 6.1.0.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Unified Inventory Management
Search vendor "Oracle" for product "Communications Unified Inventory Management"
7.3.2
Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.2"
-
Affected
Oracle
Search vendor "Oracle"
Communications Unified Inventory Management
Search vendor "Oracle" for product "Communications Unified Inventory Management"
7.3.4
Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.4"
-
Affected
Oracle
Search vendor "Oracle"
Communications Unified Inventory Management
Search vendor "Oracle" for product "Communications Unified Inventory Management"
7.3.5
Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.5"
-
Affected
Oracle
Search vendor "Oracle"
Communications Unified Inventory Management
Search vendor "Oracle" for product "Communications Unified Inventory Management"
7.4.0
Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Endeca Information Discovery Integrator
Search vendor "Oracle" for product "Endeca Information Discovery Integrator"
3.1.0
Search vendor "Oracle" for product "Endeca Information Discovery Integrator" and version "3.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Endeca Information Discovery Integrator
Search vendor "Oracle" for product "Endeca Information Discovery Integrator"
3.2.0
Search vendor "Oracle" for product "Endeca Information Discovery Integrator" and version "3.2.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager Base Platform
Search vendor "Oracle" for product "Enterprise Manager Base Platform"
12.1.0.5.0
Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "12.1.0.5.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager Base Platform
Search vendor "Oracle" for product "Enterprise Manager Base Platform"
13.2.0.0.0
Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "13.2.0.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager Base Platform
Search vendor "Oracle" for product "Enterprise Manager Base Platform"
13.3.0.0.0
Search vendor "Oracle" for product "Enterprise Manager Base Platform" and version "13.3.0.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager For Mysql Database
Search vendor "Oracle" for product "Enterprise Manager For Mysql Database"
13.2
Search vendor "Oracle" for product "Enterprise Manager For Mysql Database" and version "13.2"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager Ops Center
Search vendor "Oracle" for product "Enterprise Manager Ops Center"
12.3.3
Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.3.3"
-
Affected
Oracle
Search vendor "Oracle"
Flexcube Private Banking
Search vendor "Oracle" for product "Flexcube Private Banking"
2.0.0.0
Search vendor "Oracle" for product "Flexcube Private Banking" and version "2.0.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Flexcube Private Banking
Search vendor "Oracle" for product "Flexcube Private Banking"
2.2.0.1
Search vendor "Oracle" for product "Flexcube Private Banking" and version "2.2.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Flexcube Private Banking
Search vendor "Oracle" for product "Flexcube Private Banking"
12.0.1.0
Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.0.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Flexcube Private Banking
Search vendor "Oracle" for product "Flexcube Private Banking"
12.0.3.0
Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.0.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Flexcube Private Banking
Search vendor "Oracle" for product "Flexcube Private Banking"
12.1.0.0
Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.1.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Goldengate For Big Data
Search vendor "Oracle" for product "Goldengate For Big Data"
12.2.0.1
Search vendor "Oracle" for product "Goldengate For Big Data" and version "12.2.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Goldengate For Big Data
Search vendor "Oracle" for product "Goldengate For Big Data"
12.3.1.1
Search vendor "Oracle" for product "Goldengate For Big Data" and version "12.3.1.1"
-
Affected
Oracle
Search vendor "Oracle"
Goldengate For Big Data
Search vendor "Oracle" for product "Goldengate For Big Data"
12.3.2.1
Search vendor "Oracle" for product "Goldengate For Big Data" and version "12.3.2.1"
-
Affected
Oracle
Search vendor "Oracle"
Health Sciences Information Manager
Search vendor "Oracle" for product "Health Sciences Information Manager"
3.0
Search vendor "Oracle" for product "Health Sciences Information Manager" and version "3.0"
-
Affected
Oracle
Search vendor "Oracle"
Healthcare Master Person Index
Search vendor "Oracle" for product "Healthcare Master Person Index"
3.0
Search vendor "Oracle" for product "Healthcare Master Person Index" and version "3.0"
-
Affected
Oracle
Search vendor "Oracle"
Healthcare Master Person Index
Search vendor "Oracle" for product "Healthcare Master Person Index"
4.0
Search vendor "Oracle" for product "Healthcare Master Person Index" and version "4.0"
-
Affected
Oracle
Search vendor "Oracle"
Hospitality Guest Access
Search vendor "Oracle" for product "Hospitality Guest Access"
4.2.0
Search vendor "Oracle" for product "Hospitality Guest Access" and version "4.2.0"
-
Affected
Oracle
Search vendor "Oracle"
Hospitality Guest Access
Search vendor "Oracle" for product "Hospitality Guest Access"
4.2.1
Search vendor "Oracle" for product "Hospitality Guest Access" and version "4.2.1"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Calculation Engine
Search vendor "Oracle" for product "Insurance Calculation Engine"
10.1.1
Search vendor "Oracle" for product "Insurance Calculation Engine" and version "10.1.1"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Calculation Engine
Search vendor "Oracle" for product "Insurance Calculation Engine"
10.2
Search vendor "Oracle" for product "Insurance Calculation Engine" and version "10.2"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Calculation Engine
Search vendor "Oracle" for product "Insurance Calculation Engine"
10.2.1
Search vendor "Oracle" for product "Insurance Calculation Engine" and version "10.2.1"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Rules Palette
Search vendor "Oracle" for product "Insurance Rules Palette"
10.0
Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.0"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Rules Palette
Search vendor "Oracle" for product "Insurance Rules Palette"
10.1
Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.1"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Rules Palette
Search vendor "Oracle" for product "Insurance Rules Palette"
10.2
Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.2"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Rules Palette
Search vendor "Oracle" for product "Insurance Rules Palette"
11.0
Search vendor "Oracle" for product "Insurance Rules Palette" and version "11.0"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Rules Palette
Search vendor "Oracle" for product "Insurance Rules Palette"
11.1
Search vendor "Oracle" for product "Insurance Rules Palette" and version "11.1"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Gateway
Search vendor "Oracle" for product "Primavera Gateway"
15.2
Search vendor "Oracle" for product "Primavera Gateway" and version "15.2"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Gateway
Search vendor "Oracle" for product "Primavera Gateway"
16.2
Search vendor "Oracle" for product "Primavera Gateway" and version "16.2"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Gateway
Search vendor "Oracle" for product "Primavera Gateway"
17.12
Search vendor "Oracle" for product "Primavera Gateway" and version "17.12"
-
Affected
Oracle
Search vendor "Oracle"
Retail Customer Insights
Search vendor "Oracle" for product "Retail Customer Insights"
15.0
Search vendor "Oracle" for product "Retail Customer Insights" and version "15.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Customer Insights
Search vendor "Oracle" for product "Retail Customer Insights"
16.0
Search vendor "Oracle" for product "Retail Customer Insights" and version "16.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Open Commerce Platform
Search vendor "Oracle" for product "Retail Open Commerce Platform"
5.3.0
Search vendor "Oracle" for product "Retail Open Commerce Platform" and version "5.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Open Commerce Platform
Search vendor "Oracle" for product "Retail Open Commerce Platform"
6.0.0
Search vendor "Oracle" for product "Retail Open Commerce Platform" and version "6.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Open Commerce Platform
Search vendor "Oracle" for product "Retail Open Commerce Platform"
6.0.1
Search vendor "Oracle" for product "Retail Open Commerce Platform" and version "6.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Order Broker
Search vendor "Oracle" for product "Retail Order Broker"
5.1
Search vendor "Oracle" for product "Retail Order Broker" and version "5.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Order Broker
Search vendor "Oracle" for product "Retail Order Broker"
5.2
Search vendor "Oracle" for product "Retail Order Broker" and version "5.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Order Broker
Search vendor "Oracle" for product "Retail Order Broker"
15.0
Search vendor "Oracle" for product "Retail Order Broker" and version "15.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Order Broker
Search vendor "Oracle" for product "Retail Order Broker"
16.0
Search vendor "Oracle" for product "Retail Order Broker" and version "16.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Predictive Application Server
Search vendor "Oracle" for product "Retail Predictive Application Server"
14.0
Search vendor "Oracle" for product "Retail Predictive Application Server" and version "14.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Predictive Application Server
Search vendor "Oracle" for product "Retail Predictive Application Server"
14.1
Search vendor "Oracle" for product "Retail Predictive Application Server" and version "14.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Predictive Application Server
Search vendor "Oracle" for product "Retail Predictive Application Server"
15.0
Search vendor "Oracle" for product "Retail Predictive Application Server" and version "15.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Predictive Application Server
Search vendor "Oracle" for product "Retail Predictive Application Server"
16.0
Search vendor "Oracle" for product "Retail Predictive Application Server" and version "16.0"
-
Affected
Oracle
Search vendor "Oracle"
Service Architecture Leveraging Tuxedo
Search vendor "Oracle" for product "Service Architecture Leveraging Tuxedo"
12.1.3.0.0
Search vendor "Oracle" for product "Service Architecture Leveraging Tuxedo" and version "12.1.3.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Service Architecture Leveraging Tuxedo
Search vendor "Oracle" for product "Service Architecture Leveraging Tuxedo"
12.2.2.0.0
Search vendor "Oracle" for product "Service Architecture Leveraging Tuxedo" and version "12.2.2.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Tape Library Acsls
Search vendor "Oracle" for product "Tape Library Acsls"
8.4
Search vendor "Oracle" for product "Tape Library Acsls" and version "8.4"
-
Affected
Oracle
Search vendor "Oracle"
Utilities Network Management System
Search vendor "Oracle" for product "Utilities Network Management System"
1.12.0.3
Search vendor "Oracle" for product "Utilities Network Management System" and version "1.12.0.3"
-
Affected
Oracle
Search vendor "Oracle"
Weblogic Server
Search vendor "Oracle" for product "Weblogic Server"
10.3.6.0.0
Search vendor "Oracle" for product "Weblogic Server" and version "10.3.6.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Weblogic Server
Search vendor "Oracle" for product "Weblogic Server"
12.1.3.0.0
Search vendor "Oracle" for product "Weblogic Server" and version "12.1.3.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Weblogic Server
Search vendor "Oracle" for product "Weblogic Server"
12.2.1.3.0
Search vendor "Oracle" for product "Weblogic Server" and version "12.2.1.3.0"
-
Affected