← All CVEs

CVE-2018-1270

critical · 9.8

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.

9.8
CVSS
77.5%
EPSS (exploit prob.)
100th
EPSS percentile
2018-04-06
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-94CWE-358

Affected products

VendorProductAffected versions
vmwarespring_framework< 4.3.16
vmwarespring_framework>= 5.0.0, < 5.0.5
oracleapplication_testing_suite12.5.0.3
oracleapplication_testing_suite13.1.0.1
oracleapplication_testing_suite13.2.0.1
oracleapplication_testing_suite13.3.0.1
oraclebig_data_discovery1.6.0
oraclecommunications_converged_application_server< 7.0.0.1
oraclecommunications_diameter_signaling_router< 8.3
oraclecommunications_performance_intelligence_center< 10.2.1
oraclecommunications_services_gatekeeper< 6.1.0.4.0
oracleenterprise_manager_ops_center12.2.2
oracleenterprise_manager_ops_center12.3.3
oraclegoldengate_for_big_data12.2.0.1
oraclegoldengate_for_big_data12.3.1.1
oraclegoldengate_for_big_data12.3.2.1
oraclehealth_sciences_information_manager3.0
oraclehealthcare_master_person_index3.0
oraclehealthcare_master_person_index4.0
oracleinsurance_calculation_engine10.1.1
oracleinsurance_calculation_engine10.2
oracleinsurance_calculation_engine10.2.1
oracleinsurance_rules_palette10.0
oracleinsurance_rules_palette10.1
oracleinsurance_rules_palette10.2
oracleinsurance_rules_palette11.0
oracleinsurance_rules_palette11.1
oracleprimavera_gateway15.2
oracleprimavera_gateway16.2
oracleprimavera_gateway17.12
oracleretail_back_office14.0
oracleretail_back_office14.1
oracleretail_central_office14.0
oracleretail_central_office14.1
oracleretail_customer_insights15.0
oracleretail_customer_insights16.0
oracleretail_integration_bus14.0.1
oracleretail_integration_bus14.0.2
oracleretail_integration_bus14.0.3
oracleretail_integration_bus14.0.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-1270