CVE-2018-15756
Vmware Spring Framework
Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack. This vulnerability affects applications that depend on either spring-webmvc or spring-webflux. Such applications must also have a registration for serving static resources (e.g. JS, CSS, images, and others), or have an annotated controller that returns an org.springframework.core.io.Resource. Spring Boot applications that depend on spring-boot-starter-web or spring-boot-starter-webflux are ready to serve static resources out of the box and are therefore vulnerable.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, no account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 7.5 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Assigned by
- security_alert@emc.com
Dates
- Published
- 2018-10-18
- Last modified
- 2026-08-25
- Sources
- NVD
Affected products
- Vmware Spring Framework4.2.0 - 4.3.20, 5.0.0 - 5.0.10, 5.1.0
- Oracle Agile Product Lifecycle Management9.3.3, 9.3.4, 9.3.5, 9.3.6
- Oracle Communications Brm - Elastic Charging Engine11.3, 12.0
- Oracle Communications Converged Application Server - Service Controller6.0, 6.1
- Oracle Communications Diameter Signaling Router8.0.0, 8.1, 8.2, 8.2.1
- Oracle Communications Element Manager8.1.1, 8.2.0, 8.2.1
- Oracle Communications Online Mediation Controller6.1
- Oracle Communications Session Report Manager8.0.0, 8.1.0, 8.1.1, 8.2.0, 8.2.1
- Oracle Communications Session Route Manager8.0.0, 8.1.0, 8.1.1, 8.2.0, 8.2.1
- Oracle Communications Unified Inventory Management7.3, 7.4.0
- Oracle Endeca Information Discovery Integrator3.2.0
- Oracle Enterprise Manager For Fusion Applications13.3.0.0
As listed in the NVD configuration data. Not a statement about your estate.
References
- http://www.securityfocus.com/bid/105703
- https://lists.apache.org/thread.html/339fd112517e4873695b5115b96acdddbfc8f83b10598528d37c7d12%40%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/77886fec378ee6064debb1efb6b464a4a0173b2ff0d151ed86d3a228%40%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/7b156ee50ba3ecce87b33c06bf7a749d84ffee55e69bfb5eca88fcc3%40%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/8a1fe70534fc52ff5c9db5ac29c55657f802cbefd7e9d9850c7052bd%40%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/a3071e11c6fbd593022074ec1b4693f6d948c2b02cfa4a5d854aed68%40%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/bb354962cb51fff65740d5fb1bc2aac56af577c06244b57c36f98e4d%40%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/d6a84f52db89804b0ad965f3ea2b24bb880edee29107a1c5069cc3dd%40%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/efaa52b0aa67aae7cbd9e6ef96945387e422d7ce0e65434570a37b1d%40%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/f8905507a2c94af6b08b72d7be0c4b8c6660e585f00abfafeccc86bc%40%3Cissues.activemq.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html
- https://pivotal.io/security/cve-2018-15756
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpujan2020.html