// For flags

CVE-2018-1270

spring-framework: Possible RCE via spring messaging

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.

Spring Framework, en versiones 5.0 anteriores a la 5.0.5 y versiones 4.3 anteriores a la 4.3.15, así como versiones más antiguas no soportadas, permite que las aplicaciones expongan STOMP en endpoints WebSocket con un simple agente STOMP en memoria a través del módulo spring-messaging. Un usuario (o atacante) malicioso puede manipular un mensaje al agente que desemboca en un ataque de ejecución remota de código.

Pivotal Spring Java Framework versions 5.0.x and below suffer from a remote code execution vulnerability.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-12-06 CVE Reserved
  • 2018-04-06 CVE Published
  • 2018-04-12 First Exploit
  • 2024-09-16 CVE Updated
  • 2024-11-07 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-20: Improper Input Validation
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
  • CWE-358: Improperly Implemented Security Check for Standard
CAPEC
References (21)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Vmware
Search vendor "Vmware"
Spring Framework
Search vendor "Vmware" for product "Spring Framework"
< 4.3.16
Search vendor "Vmware" for product "Spring Framework" and version " < 4.3.16"
-
Affected
Vmware
Search vendor "Vmware"
Spring Framework
Search vendor "Vmware" for product "Spring Framework"
>= 5.0.0 < 5.0.5
Search vendor "Vmware" for product "Spring Framework" and version " >= 5.0.0 < 5.0.5"
-
Affected
Oracle
Search vendor "Oracle"
Application Testing Suite
Search vendor "Oracle" for product "Application Testing Suite"
12.5.0.3
Search vendor "Oracle" for product "Application Testing Suite" and version "12.5.0.3"
-
Affected
Oracle
Search vendor "Oracle"
Application Testing Suite
Search vendor "Oracle" for product "Application Testing Suite"
13.1.0.1
Search vendor "Oracle" for product "Application Testing Suite" and version "13.1.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Application Testing Suite
Search vendor "Oracle" for product "Application Testing Suite"
13.2.0.1
Search vendor "Oracle" for product "Application Testing Suite" and version "13.2.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Application Testing Suite
Search vendor "Oracle" for product "Application Testing Suite"
13.3.0.1
Search vendor "Oracle" for product "Application Testing Suite" and version "13.3.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Big Data Discovery
Search vendor "Oracle" for product "Big Data Discovery"
1.6.0
Search vendor "Oracle" for product "Big Data Discovery" and version "1.6.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Converged Application Server
Search vendor "Oracle" for product "Communications Converged Application Server"
< 7.0.0.1
Search vendor "Oracle" for product "Communications Converged Application Server" and version " < 7.0.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Diameter Signaling Router
Search vendor "Oracle" for product "Communications Diameter Signaling Router"
< 8.3
Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version " < 8.3"
-
Affected
Oracle
Search vendor "Oracle"
Communications Performance Intelligence Center
Search vendor "Oracle" for product "Communications Performance Intelligence Center"
< 10.2.1
Search vendor "Oracle" for product "Communications Performance Intelligence Center" and version " < 10.2.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Services Gatekeeper
Search vendor "Oracle" for product "Communications Services Gatekeeper"
< 6.1.0.4.0
Search vendor "Oracle" for product "Communications Services Gatekeeper" and version " < 6.1.0.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager Ops Center
Search vendor "Oracle" for product "Enterprise Manager Ops Center"
12.2.2
Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.2.2"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Manager Ops Center
Search vendor "Oracle" for product "Enterprise Manager Ops Center"
12.3.3
Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.3.3"
-
Affected
Oracle
Search vendor "Oracle"
Goldengate For Big Data
Search vendor "Oracle" for product "Goldengate For Big Data"
12.2.0.1
Search vendor "Oracle" for product "Goldengate For Big Data" and version "12.2.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Goldengate For Big Data
Search vendor "Oracle" for product "Goldengate For Big Data"
12.3.1.1
Search vendor "Oracle" for product "Goldengate For Big Data" and version "12.3.1.1"
-
Affected
Oracle
Search vendor "Oracle"
Goldengate For Big Data
Search vendor "Oracle" for product "Goldengate For Big Data"
12.3.2.1
Search vendor "Oracle" for product "Goldengate For Big Data" and version "12.3.2.1"
-
Affected
Oracle
Search vendor "Oracle"
Health Sciences Information Manager
Search vendor "Oracle" for product "Health Sciences Information Manager"
3.0
Search vendor "Oracle" for product "Health Sciences Information Manager" and version "3.0"
-
Affected
Oracle
Search vendor "Oracle"
Healthcare Master Person Index
Search vendor "Oracle" for product "Healthcare Master Person Index"
3.0
Search vendor "Oracle" for product "Healthcare Master Person Index" and version "3.0"
-
Affected
Oracle
Search vendor "Oracle"
Healthcare Master Person Index
Search vendor "Oracle" for product "Healthcare Master Person Index"
4.0
Search vendor "Oracle" for product "Healthcare Master Person Index" and version "4.0"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Calculation Engine
Search vendor "Oracle" for product "Insurance Calculation Engine"
10.1.1
Search vendor "Oracle" for product "Insurance Calculation Engine" and version "10.1.1"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Calculation Engine
Search vendor "Oracle" for product "Insurance Calculation Engine"
10.2
Search vendor "Oracle" for product "Insurance Calculation Engine" and version "10.2"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Calculation Engine
Search vendor "Oracle" for product "Insurance Calculation Engine"
10.2.1
Search vendor "Oracle" for product "Insurance Calculation Engine" and version "10.2.1"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Rules Palette
Search vendor "Oracle" for product "Insurance Rules Palette"
10.0
Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.0"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Rules Palette
Search vendor "Oracle" for product "Insurance Rules Palette"
10.1
Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.1"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Rules Palette
Search vendor "Oracle" for product "Insurance Rules Palette"
10.2
Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.2"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Rules Palette
Search vendor "Oracle" for product "Insurance Rules Palette"
11.0
Search vendor "Oracle" for product "Insurance Rules Palette" and version "11.0"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Rules Palette
Search vendor "Oracle" for product "Insurance Rules Palette"
11.1
Search vendor "Oracle" for product "Insurance Rules Palette" and version "11.1"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Gateway
Search vendor "Oracle" for product "Primavera Gateway"
15.2
Search vendor "Oracle" for product "Primavera Gateway" and version "15.2"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Gateway
Search vendor "Oracle" for product "Primavera Gateway"
16.2
Search vendor "Oracle" for product "Primavera Gateway" and version "16.2"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Gateway
Search vendor "Oracle" for product "Primavera Gateway"
17.12
Search vendor "Oracle" for product "Primavera Gateway" and version "17.12"
-
Affected
Oracle
Search vendor "Oracle"
Retail Back Office
Search vendor "Oracle" for product "Retail Back Office"
14.0
Search vendor "Oracle" for product "Retail Back Office" and version "14.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Back Office
Search vendor "Oracle" for product "Retail Back Office"
14.1
Search vendor "Oracle" for product "Retail Back Office" and version "14.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Central Office
Search vendor "Oracle" for product "Retail Central Office"
14.0
Search vendor "Oracle" for product "Retail Central Office" and version "14.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Central Office
Search vendor "Oracle" for product "Retail Central Office"
14.1
Search vendor "Oracle" for product "Retail Central Office" and version "14.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Customer Insights
Search vendor "Oracle" for product "Retail Customer Insights"
15.0
Search vendor "Oracle" for product "Retail Customer Insights" and version "15.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Customer Insights
Search vendor "Oracle" for product "Retail Customer Insights"
16.0
Search vendor "Oracle" for product "Retail Customer Insights" and version "16.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
14.0.1
Search vendor "Oracle" for product "Retail Integration Bus" and version "14.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
14.0.2
Search vendor "Oracle" for product "Retail Integration Bus" and version "14.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
14.0.3
Search vendor "Oracle" for product "Retail Integration Bus" and version "14.0.3"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
14.0.4
Search vendor "Oracle" for product "Retail Integration Bus" and version "14.0.4"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
14.1.1
Search vendor "Oracle" for product "Retail Integration Bus" and version "14.1.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
14.1.2
Search vendor "Oracle" for product "Retail Integration Bus" and version "14.1.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
14.1.3
Search vendor "Oracle" for product "Retail Integration Bus" and version "14.1.3"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
15.0.0.1
Search vendor "Oracle" for product "Retail Integration Bus" and version "15.0.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
15.0.1
Search vendor "Oracle" for product "Retail Integration Bus" and version "15.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
15.0.2
Search vendor "Oracle" for product "Retail Integration Bus" and version "15.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
16.0
Search vendor "Oracle" for product "Retail Integration Bus" and version "16.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
16.0.1
Search vendor "Oracle" for product "Retail Integration Bus" and version "16.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
16.0.2
Search vendor "Oracle" for product "Retail Integration Bus" and version "16.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Open Commerce Platform
Search vendor "Oracle" for product "Retail Open Commerce Platform"
5.3.0
Search vendor "Oracle" for product "Retail Open Commerce Platform" and version "5.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Open Commerce Platform
Search vendor "Oracle" for product "Retail Open Commerce Platform"
6.0.0
Search vendor "Oracle" for product "Retail Open Commerce Platform" and version "6.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Open Commerce Platform
Search vendor "Oracle" for product "Retail Open Commerce Platform"
6.0.1
Search vendor "Oracle" for product "Retail Open Commerce Platform" and version "6.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Order Broker
Search vendor "Oracle" for product "Retail Order Broker"
5.1
Search vendor "Oracle" for product "Retail Order Broker" and version "5.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Order Broker
Search vendor "Oracle" for product "Retail Order Broker"
5.2
Search vendor "Oracle" for product "Retail Order Broker" and version "5.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Order Broker
Search vendor "Oracle" for product "Retail Order Broker"
15.0
Search vendor "Oracle" for product "Retail Order Broker" and version "15.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Order Broker
Search vendor "Oracle" for product "Retail Order Broker"
16.0
Search vendor "Oracle" for product "Retail Order Broker" and version "16.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Point-of-sale
Search vendor "Oracle" for product "Retail Point-of-sale"
14.0
Search vendor "Oracle" for product "Retail Point-of-sale" and version "14.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Point-of-sale
Search vendor "Oracle" for product "Retail Point-of-sale"
14.1
Search vendor "Oracle" for product "Retail Point-of-sale" and version "14.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Predictive Application Server
Search vendor "Oracle" for product "Retail Predictive Application Server"
14.0
Search vendor "Oracle" for product "Retail Predictive Application Server" and version "14.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Predictive Application Server
Search vendor "Oracle" for product "Retail Predictive Application Server"
14.1
Search vendor "Oracle" for product "Retail Predictive Application Server" and version "14.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Predictive Application Server
Search vendor "Oracle" for product "Retail Predictive Application Server"
15.0
Search vendor "Oracle" for product "Retail Predictive Application Server" and version "15.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Predictive Application Server
Search vendor "Oracle" for product "Retail Predictive Application Server"
16.0
Search vendor "Oracle" for product "Retail Predictive Application Server" and version "16.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Returns Management
Search vendor "Oracle" for product "Retail Returns Management"
14.0
Search vendor "Oracle" for product "Retail Returns Management" and version "14.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Returns Management
Search vendor "Oracle" for product "Retail Returns Management"
14.1
Search vendor "Oracle" for product "Retail Returns Management" and version "14.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
7.1
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "7.1"
-
Affected
Oracle
Search vendor "Oracle"
Service Architecture Leveraging Tuxedo
Search vendor "Oracle" for product "Service Architecture Leveraging Tuxedo"
12.1.3.0.0
Search vendor "Oracle" for product "Service Architecture Leveraging Tuxedo" and version "12.1.3.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Service Architecture Leveraging Tuxedo
Search vendor "Oracle" for product "Service Architecture Leveraging Tuxedo"
12.2.2.0.0
Search vendor "Oracle" for product "Service Architecture Leveraging Tuxedo" and version "12.2.2.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Tape Library Acsls
Search vendor "Oracle" for product "Tape Library Acsls"
8.4
Search vendor "Oracle" for product "Tape Library Acsls" and version "8.4"
-
Affected
Redhat
Search vendor "Redhat"
Fuse
Search vendor "Redhat" for product "Fuse"
1.0.0
Search vendor "Redhat" for product "Fuse" and version "1.0.0"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
9.0
Search vendor "Debian" for product "Debian Linux" and version "9.0"
-
Affected