CVE-2018-1275
9.8
CRITICAL · CVSS 3.1 · EPSS 57.4% (pctl 99)
Patch early
EPSS 57.4% — above the 10% action threshold.
Description
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 57.41% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-04-11 |
| Last modified | 2026-06-17 |
Affected (19)
| Vendor | Product |
|---|---|
| oracle | application testing suite |
| oracle | big data discovery |
| oracle | communications converged application server |
| oracle | communications diameter signaling router |
| oracle | communications performance intelligence center |
| oracle | communications services gatekeeper |
| oracle | goldengate for big data |
| oracle | health sciences information manager |
| oracle | healthcare master person index |
| oracle | insurance calculation engine |
| oracle | insurance rules palette |
| oracle | primavera gateway |
| oracle | retail customer insights |
| oracle | retail open commerce platform |
| oracle | retail order broker |
| oracle | retail predictive application server |
| oracle | service architecture leveraging tuxedo |
| oracle | tape library acsls |
| vmware | spring framework |
References
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/103771
- http://www.securitytracker.com/id/1041301
- https://access.redhat.com/errata/RHSA-2018:1320
- https://access.redhat.com/errata/RHSA-2018:2939
- https://lists.apache.org/thread.html/4ed49b103f64a0cecb38064f26cbf1389afc12124653da2d35166dbe%40%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/ab825fcade0b49becfa30235b3d54f4a51bb74ea96b6c9adb5d1378c%40%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369%40%3Cissues.activemq.apache.org%3E
- https://pivotal.io/security/cve-2018-1275
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/103771
- http://www.securitytracker.com/id/1041301
- https://access.redhat.com/errata/RHSA-2018:1320
- https://access.redhat.com/errata/RHSA-2018:2939
→ the Explorer · watch your stack · NVD