5.9mediumMedium
CVE-2018-11039
Vmware Spring Framework
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
- To exploit it, no account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 5.9 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N- Assigned by
- security_alert@emc.com
Dates
- Published
- 2018-06-25
- Last modified
- 2026-08-25
- Sources
- NVD
Affected products
- Vmware Spring Framework- 4.3.18, 5.0.0 - 5.0.7
- Oracle Agile Product Lifecycle Management9.3.3, 9.3.4, 9.3.5, 9.3.6
- Oracle Application Testing Suite12.5.0.3, 13.1.0.1, 13.2.0.1, 13.3.0.1
- Oracle Communications Diameter Signaling Router- 8.3
- Oracle Communications Network Integrity7.3.2 - 7.3.6
- Oracle Communications Online Mediation Controller6.1
- Oracle Communications Performance Intelligence Center- 10.2.1
- Oracle Communications Services Gatekeeper- 6.1.0.4.0
- Oracle Communications Unified Inventory Management7.3.2, 7.3.4, 7.3.5, 7.4.0
- Oracle Endeca Information Discovery Integrator3.1.0, 3.2.0
- Oracle Enterprise Manager Base Platform12.1.0.5.0, 13.2.0.0.0, 13.3.0.0.0
- Oracle Enterprise Manager For Mysql Database13.2
As listed in the NVD configuration data. Not a statement about your estate.
References
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/107984
- https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html
- https://pivotal.io/security/cve-2018-11039
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/107984
- https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html
- https://pivotal.io/security/cve-2018-11039
- https://www.oracle.com/security-alerts/cpujan2020.html