peter bassill · operator
$ cve CVE-2018-1275 JSON

CVE-2018-1275

9.8
CRITICAL · CVSS 3.1 · EPSS 57.4% (pctl 99)

Patch early

EPSS 57.4% — above the 10% action threshold.

Description

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS57.41% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploitnone known
Published2018-04-11
Last modified2026-06-17

Affected (19)

VendorProduct
oracleapplication testing suite
oraclebig data discovery
oraclecommunications converged application server
oraclecommunications diameter signaling router
oraclecommunications performance intelligence center
oraclecommunications services gatekeeper
oraclegoldengate for big data
oraclehealth sciences information manager
oraclehealthcare master person index
oracleinsurance calculation engine
oracleinsurance rules palette
oracleprimavera gateway
oracleretail customer insights
oracleretail open commerce platform
oracleretail order broker
oracleretail predictive application server
oracleservice architecture leveraging tuxedo
oracletape library acsls
vmwarespring framework

References

→ the Explorer  ·  watch your stack  ·  NVD