CVE-2018-1273 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 97% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-04-15.
Description
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 96.96% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | yes — remediate by 2022-04-15 |
| Public exploit | none known |
| Published | 2018-04-11 |
| Last modified | 2026-08-26 |
CISA KEV
| Name | VMware Tanzu Spring Data Commons Property Binder Vulnerability |
|---|---|
| Added | 2022-03-25 |
| Due | 2022-04-15 |
| Vendor / product | VMware Tanzu / Spring Data Commons |
| Ransomware use | known |
Affected (5)
| Vendor | Product |
|---|---|
| apache | ignite |
| broadcom | spring data commons |
| oracle | financial services crime and compliance management studio |
| pivotal software | spring data rest |
| vmware | spring data rest |
References
- http://mail-archives.apache.org/mod_mbox/ignite-dev/201807.mbox/%3CCAK0qHnqzfzmCDFFi6c5Jok19zNkVCz5Xb4sU%3D0f2J_1i4p46zQ%40mail.gmail.com%3E
- https://pivotal.io/security/cve-2018-1273
- https://www.oracle.com/security-alerts/cpujul2022.html
- http://mail-archives.apache.org/mod_mbox/ignite-dev/201807.mbox/%3CCAK0qHnqzfzmCDFFi6c5Jok19zNkVCz5Xb4sU%3D0f2J_1i4p46zQ%40mail.gmail.com%3E
- https://pivotal.io/security/cve-2018-1273
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-1273
→ the Explorer · watch your stack · NVD