CVE-2018-1272
spring-framework: Multipart content pollution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.
Spring Framework, en versiones 5.0 anteriores a la 5.0.5 y versiones 4.3 anteriores a la 4.3.15, así como versiones más antiguas no soportadas, proporciona soporte del lado de cliente a peticiones multipart. Cuando las aplicaciones Spring MVC o Spring WebFlux (servidor A) reciben entradas de un cliente remoto y, a continuación, emplea esa entrada para realizar una petición multipart a otro servidor (servidor B), pueden verse expuestas a un ataque en el que un multipart extra se inserta en el contenido de la petición del servidor A. Esto provoca que servidor B emplee el valor incorrecto para una parte que espera. Esto podría desembocar en el escalado de privilegios, por ejemplo, si el contenido part representa a un nombre de usuario o a roles de usuario.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-06 CVE Reserved
- 2018-04-06 CVE Published
- 2024-05-31 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/103697 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2018:1320 | 2022-06-23 | |
https://access.redhat.com/errata/RHSA-2018:2669 | 2022-06-23 | |
https://pivotal.io/security/cve-2018-1272 | 2022-06-23 | |
https://access.redhat.com/security/cve/CVE-2018-1272 | 2018-09-11 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1564408 | 2018-09-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vmware Search vendor "Vmware" | Spring Framework Search vendor "Vmware" for product "Spring Framework" | >= 4.3.0 < 4.3.15 Search vendor "Vmware" for product "Spring Framework" and version " >= 4.3.0 < 4.3.15" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Spring Framework Search vendor "Vmware" for product "Spring Framework" | >= 5.0 < 5.0.5 Search vendor "Vmware" for product "Spring Framework" and version " >= 5.0 < 5.0.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 12.5.0.3 Search vendor "Oracle" for product "Application Testing Suite" and version "12.5.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 13.1.0.1 Search vendor "Oracle" for product "Application Testing Suite" and version "13.1.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 13.2.0.1 Search vendor "Oracle" for product "Application Testing Suite" and version "13.2.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Testing Suite Search vendor "Oracle" for product "Application Testing Suite" | 13.3.0.1 Search vendor "Oracle" for product "Application Testing Suite" and version "13.3.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Big Data Discovery Search vendor "Oracle" for product "Big Data Discovery" | 1.6.0 Search vendor "Oracle" for product "Big Data Discovery" and version "1.6.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Converged Application Server Search vendor "Oracle" for product "Communications Converged Application Server" | < 7.0.0.1 Search vendor "Oracle" for product "Communications Converged Application Server" and version " < 7.0.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Diameter Signaling Router Search vendor "Oracle" for product "Communications Diameter Signaling Router" | < 8.3 Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version " < 8.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Performance Intelligence Center Search vendor "Oracle" for product "Communications Performance Intelligence Center" | < 10.2.1 Search vendor "Oracle" for product "Communications Performance Intelligence Center" and version " < 10.2.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Services Gatekeeper Search vendor "Oracle" for product "Communications Services Gatekeeper" | < 6.1.0.4.0 Search vendor "Oracle" for product "Communications Services Gatekeeper" and version " < 6.1.0.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Ops Center Search vendor "Oracle" for product "Enterprise Manager Ops Center" | 12.2.2 Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.2.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Ops Center Search vendor "Oracle" for product "Enterprise Manager Ops Center" | 12.3.3 Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.3.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Goldengate For Big Data Search vendor "Oracle" for product "Goldengate For Big Data" | 12.2.0.1 Search vendor "Oracle" for product "Goldengate For Big Data" and version "12.2.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Goldengate For Big Data Search vendor "Oracle" for product "Goldengate For Big Data" | 12.3.1.1 Search vendor "Oracle" for product "Goldengate For Big Data" and version "12.3.1.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Goldengate For Big Data Search vendor "Oracle" for product "Goldengate For Big Data" | 12.3.2.1 Search vendor "Oracle" for product "Goldengate For Big Data" and version "12.3.2.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Health Sciences Information Manager Search vendor "Oracle" for product "Health Sciences Information Manager" | 3.0 Search vendor "Oracle" for product "Health Sciences Information Manager" and version "3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Healthcare Master Person Index Search vendor "Oracle" for product "Healthcare Master Person Index" | 3.0 Search vendor "Oracle" for product "Healthcare Master Person Index" and version "3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Healthcare Master Person Index Search vendor "Oracle" for product "Healthcare Master Person Index" | 4.0 Search vendor "Oracle" for product "Healthcare Master Person Index" and version "4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Calculation Engine Search vendor "Oracle" for product "Insurance Calculation Engine" | 10.1.1 Search vendor "Oracle" for product "Insurance Calculation Engine" and version "10.1.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Calculation Engine Search vendor "Oracle" for product "Insurance Calculation Engine" | 10.2 Search vendor "Oracle" for product "Insurance Calculation Engine" and version "10.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Calculation Engine Search vendor "Oracle" for product "Insurance Calculation Engine" | 10.2.1 Search vendor "Oracle" for product "Insurance Calculation Engine" and version "10.2.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 10.0 Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 10.1 Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 10.2 Search vendor "Oracle" for product "Insurance Rules Palette" and version "10.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 11.0 Search vendor "Oracle" for product "Insurance Rules Palette" and version "11.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Rules Palette Search vendor "Oracle" for product "Insurance Rules Palette" | 11.1 Search vendor "Oracle" for product "Insurance Rules Palette" and version "11.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Gateway Search vendor "Oracle" for product "Primavera Gateway" | 15.2 Search vendor "Oracle" for product "Primavera Gateway" and version "15.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Gateway Search vendor "Oracle" for product "Primavera Gateway" | 16.2 Search vendor "Oracle" for product "Primavera Gateway" and version "16.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Gateway Search vendor "Oracle" for product "Primavera Gateway" | 17.12 Search vendor "Oracle" for product "Primavera Gateway" and version "17.12" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Back Office Search vendor "Oracle" for product "Retail Back Office" | 14.0 Search vendor "Oracle" for product "Retail Back Office" and version "14.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Back Office Search vendor "Oracle" for product "Retail Back Office" | 14.1 Search vendor "Oracle" for product "Retail Back Office" and version "14.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Central Office Search vendor "Oracle" for product "Retail Central Office" | 14.0 Search vendor "Oracle" for product "Retail Central Office" and version "14.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Central Office Search vendor "Oracle" for product "Retail Central Office" | 14.1 Search vendor "Oracle" for product "Retail Central Office" and version "14.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Customer Insights Search vendor "Oracle" for product "Retail Customer Insights" | 15.0 Search vendor "Oracle" for product "Retail Customer Insights" and version "15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Customer Insights Search vendor "Oracle" for product "Retail Customer Insights" | 16.0 Search vendor "Oracle" for product "Retail Customer Insights" and version "16.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 14.0.1 Search vendor "Oracle" for product "Retail Integration Bus" and version "14.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 14.0.2 Search vendor "Oracle" for product "Retail Integration Bus" and version "14.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 14.0.3 Search vendor "Oracle" for product "Retail Integration Bus" and version "14.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 14.0.4 Search vendor "Oracle" for product "Retail Integration Bus" and version "14.0.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 14.1.1 Search vendor "Oracle" for product "Retail Integration Bus" and version "14.1.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 14.1.2 Search vendor "Oracle" for product "Retail Integration Bus" and version "14.1.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 14.1.3 Search vendor "Oracle" for product "Retail Integration Bus" and version "14.1.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 15.0.0.1 Search vendor "Oracle" for product "Retail Integration Bus" and version "15.0.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 15.0.1 Search vendor "Oracle" for product "Retail Integration Bus" and version "15.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 15.0.2 Search vendor "Oracle" for product "Retail Integration Bus" and version "15.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 16.0 Search vendor "Oracle" for product "Retail Integration Bus" and version "16.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 16.0.1 Search vendor "Oracle" for product "Retail Integration Bus" and version "16.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 16.0.2 Search vendor "Oracle" for product "Retail Integration Bus" and version "16.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Open Commerce Platform Search vendor "Oracle" for product "Retail Open Commerce Platform" | 5.3.0 Search vendor "Oracle" for product "Retail Open Commerce Platform" and version "5.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Open Commerce Platform Search vendor "Oracle" for product "Retail Open Commerce Platform" | 6.0.0 Search vendor "Oracle" for product "Retail Open Commerce Platform" and version "6.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Open Commerce Platform Search vendor "Oracle" for product "Retail Open Commerce Platform" | 6.0.1 Search vendor "Oracle" for product "Retail Open Commerce Platform" and version "6.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Order Broker Search vendor "Oracle" for product "Retail Order Broker" | 5.1 Search vendor "Oracle" for product "Retail Order Broker" and version "5.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Order Broker Search vendor "Oracle" for product "Retail Order Broker" | 5.2 Search vendor "Oracle" for product "Retail Order Broker" and version "5.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Order Broker Search vendor "Oracle" for product "Retail Order Broker" | 15.0 Search vendor "Oracle" for product "Retail Order Broker" and version "15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Order Broker Search vendor "Oracle" for product "Retail Order Broker" | 16.0 Search vendor "Oracle" for product "Retail Order Broker" and version "16.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Point-of-sale Search vendor "Oracle" for product "Retail Point-of-sale" | 14.0 Search vendor "Oracle" for product "Retail Point-of-sale" and version "14.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Point-of-sale Search vendor "Oracle" for product "Retail Point-of-sale" | 14.1 Search vendor "Oracle" for product "Retail Point-of-sale" and version "14.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 14.0 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "14.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 14.1 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "14.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 15.0 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 16.0 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "16.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Returns Management Search vendor "Oracle" for product "Retail Returns Management" | 14.0 Search vendor "Oracle" for product "Retail Returns Management" and version "14.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Returns Management Search vendor "Oracle" for product "Retail Returns Management" | 14.1 Search vendor "Oracle" for product "Retail Returns Management" and version "14.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Service Architecture Leveraging Tuxedo Search vendor "Oracle" for product "Service Architecture Leveraging Tuxedo" | 12.1.3.0.0 Search vendor "Oracle" for product "Service Architecture Leveraging Tuxedo" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Service Architecture Leveraging Tuxedo Search vendor "Oracle" for product "Service Architecture Leveraging Tuxedo" | 12.2.2.0.0 Search vendor "Oracle" for product "Service Architecture Leveraging Tuxedo" and version "12.2.2.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Tape Library Acsls Search vendor "Oracle" for product "Tape Library Acsls" | 8.4 Search vendor "Oracle" for product "Tape Library Acsls" and version "8.4" | - |
Affected
|