peter bassill · operator
$ cve CVE-2018-1273 JSON

CVE-2018-1273 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 97% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-15.

Description

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS96.96% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-94
On CISA KEVyes — remediate by 2022-04-15
Public exploitnone known
Published2018-04-11
Last modified2026-08-26

CISA KEV

NameVMware Tanzu Spring Data Commons Property Binder Vulnerability
Added2022-03-25
Due2022-04-15
Vendor / productVMware Tanzu / Spring Data Commons
Ransomware useknown

Affected (5)

VendorProduct
apacheignite
broadcomspring data commons
oraclefinancial services crime and compliance management studio
pivotal softwarespring data rest
vmwarespring data rest

References

→ the Explorer  ·  watch your stack  ·  NVD