CVE-2018-1258
Summary
| CVE | CVE-2018-1258 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-11 20:29:00 UTC |
| Updated | 2022-04-11 17:18:00 UTC |
| Description | Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Netapp | Oncommand Insight | - | All | All | All |
| Application | Netapp | Oncommand Insight | - | All | All | All |
| Application | Netapp | Oncommand Unified Manager | All | All | All | All |
| Application | Netapp | Oncommand Unified Manager | All | All | All | All |
| Application | Netapp | Oncommand Unified Manager | All | All | All | All |
| Application | Netapp | Oncommand Unified Manager | All | All | All | All |
| Application | Netapp | Oncommand Workflow Automation | - | All | All | All |
| Application | Netapp | Oncommand Workflow Automation | - | All | All | All |
| Application | Netapp | Snapcenter | - | All | All | All |
| Application | Netapp | Snapcenter | - | All | All | All |
| Application | Netapp | Storage Automation Store | - | All | All | All |
| Application | Netapp | Storage Automation Store | - | All | All | All |
| Application | Oracle | Agile Plm | 9.3.3 | All | All | All |
| Application | Oracle | Agile Plm | 9.3.4 | All | All | All |
| Application | Oracle | Agile Plm | 9.3.5 | All | All | All |
| Application | Oracle | Agile Plm | 9.3.6 | All | All | All |
| Application | Oracle | Agile Plm | 9.3.3 | All | All | All |
| Application | Oracle | Agile Plm | 9.3.4 | All | All | All |
| Application | Oracle | Agile Plm | 9.3.5 | All | All | All |
| Application | Oracle | Agile Plm | 9.3.6 | All | All | All |
| Application | Oracle | Application Testing Suite | 10.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 12.5.0.3 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.1.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.2.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.3.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 10.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 12.5.0.3 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.1.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.2.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.3.0.1 | All | All | All |
| Application | Oracle | Big Data Discovery | 1.6.0 | All | All | All |
| Application | Oracle | Big Data Discovery | 1.6.0 | All | All | All |
| Application | Oracle | Communications Converged Application Server | All | All | All | All |
| Application | Oracle | Communications Converged Application Server | All | All | All | All |
| Application | Oracle | Communications Diameter Signaling Router | All | All | All | All |
| Application | Oracle | Communications Diameter Signaling Router | All | All | All | All |
| Application | Oracle | Communications Network Integrity | All | All | All | All |
| Application | Oracle | Communications Performance Intelligence Center | All | All | All | All |
| Application | Oracle | Communications Performance Intelligence Center | All | All | All | All |
| Application | Oracle | Communications Services Gatekeeper | All | All | All | All |
| Application | Oracle | Communications Services Gatekeeper | All | All | All | All |
| Application | Oracle | Endeca Information Discovery Integrator | 3.1.0 | All | All | All |
| Application | Oracle | Endeca Information Discovery Integrator | 3.2.0 | All | All | All |
| Application | Oracle | Endeca Information Discovery Integrator | 3.1.0 | All | All | All |
| Application | Oracle | Endeca Information Discovery Integrator | 3.2.0 | All | All | All |
| Application | Oracle | Enterprise Manager For Mysql Database | 13.2 | All | All | All |
| Application | Oracle | Enterprise Manager For Mysql Database | 13.2 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.2.2 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.3.3 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.2.2 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.3.3 | All | All | All |
| Application | Oracle | Enterprise Repository | 11.1.1.7.0 | All | All | All |
| Application | Oracle | Enterprise Repository | 12.1.3.0.0 | All | All | All |
| Application | Oracle | Enterprise Repository | 11.1.1.7.0 | All | All | All |
| Application | Oracle | Enterprise Repository | 12.1.3.0.0 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.2.0.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.3.1.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.3.2.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.2.0.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.3.1.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.3.2.1 | All | All | All |
| Application | Oracle | Healthcare Master Person Index | 3.0 | All | All | All |
| Application | Oracle | Healthcare Master Person Index | 4.0 | All | All | All |
| Application | Oracle | Healthcare Master Person Index | 3.0 | All | All | All |
| Application | Oracle | Healthcare Master Person Index | 4.0 | All | All | All |
| Application | Oracle | Health Sciences Information Manager | 3.0 | All | All | All |
| Application | Oracle | Health Sciences Information Manager | 3.0 | All | All | All |
| Application | Oracle | Hospitality Guest Access | 4.2.0 | All | All | All |
| Application | Oracle | Hospitality Guest Access | 4.2.1 | All | All | All |
| Application | Oracle | Hospitality Guest Access | 4.2.0 | All | All | All |
| Application | Oracle | Hospitality Guest Access | 4.2.1 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.1.1 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.2 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.2.1 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.1.1 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.2 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.2.1 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 10.0 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 10.1 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 10.2 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 11.0 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 10.0 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 10.1 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 10.2 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 11.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.1 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.2 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.1 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.1 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.2 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.1 | All | All | All |
| Application | Oracle | Micros Lucas | 2.9.5 | All | All | All |
| Application | Oracle | Micros Lucas | 2.9.5 | All | All | All |
| Application | Oracle | Mysql Enterprise Monitor | All | All | All | All |
| Application | Oracle | Peoplesoft Enterprise Fin Install | 9.2 | All | All | All |
| Application | Oracle | Peoplesoft Enterprise Fin Install | 9.2 | All | All | All |
| Application | Oracle | Retail Assortment Planning | 14.1 | All | All | All |
| Application | Oracle | Retail Assortment Planning | 15.0 | All | All | All |
| Application | Oracle | Retail Assortment Planning | 16.0 | All | All | All |
| Application | Oracle | Retail Assortment Planning | 14.1 | All | All | All |
| Application | Oracle | Retail Assortment Planning | 15.0 | All | All | All |
| Application | Oracle | Retail Assortment Planning | 16.0 | All | All | All |
| Application | Oracle | Retail Back Office | 14.0 | All | All | All |
| Application | Oracle | Retail Back Office | 14.1 | All | All | All |
| Application | Oracle | Retail Back Office | 14.0 | All | All | All |
| Application | Oracle | Retail Back Office | 14.1 | All | All | All |
| Application | Oracle | Retail Central Office | 14.0 | All | All | All |
| Application | Oracle | Retail Central Office | 14.1 | All | All | All |
| Application | Oracle | Retail Central Office | 14.0 | All | All | All |
| Application | Oracle | Retail Central Office | 14.1 | All | All | All |
| Application | Oracle | Retail Customer Insights | 15.0 | All | All | All |
| Application | Oracle | Retail Customer Insights | 16.0 | All | All | All |
| Application | Oracle | Retail Customer Insights | 15.0 | All | All | All |
| Application | Oracle | Retail Customer Insights | 16.0 | All | All | All |
| Application | Oracle | Retail Financial Integration | 13.2 | All | All | All |
| Application | Oracle | Retail Financial Integration | 14.0 | All | All | All |
| Application | Oracle | Retail Financial Integration | 14.1 | All | All | All |
| Application | Oracle | Retail Financial Integration | 15.0 | All | All | All |
| Application | Oracle | Retail Financial Integration | 16.0 | All | All | All |
| Application | Oracle | Retail Financial Integration | 13.2 | All | All | All |
| Application | Oracle | Retail Financial Integration | 14.0 | All | All | All |
| Application | Oracle | Retail Financial Integration | 14.1 | All | All | All |
| Application | Oracle | Retail Financial Integration | 15.0 | All | All | All |
| Application | Oracle | Retail Financial Integration | 16.0 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.2 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.2 | All | All | All |
| Application | Oracle | Retail Point-of-service | 14.0 | All | All | All |
| Application | Oracle | Retail Point-of-service | 14.1 | All | All | All |
| Application | Oracle | Retail Point-of-service | 14.0 | All | All | All |
| Application | Oracle | Retail Point-of-service | 14.1 | All | All | All |
| Application | Oracle | Retail Returns Management | 14.0 | All | All | All |
| Application | Oracle | Retail Returns Management | 14.1 | All | All | All |
| Application | Oracle | Retail Returns Management | 14.0 | All | All | All |
| Application | Oracle | Retail Returns Management | 14.1 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 17.0 | All | All | All |
| Application | Oracle | Service Architecture Leveraging Tuxedo | 12.1.3.0.0 | All | All | All |
| Application | Oracle | Service Architecture Leveraging Tuxedo | 12.2.2.0.0 | All | All | All |
| Application | Oracle | Service Architecture Leveraging Tuxedo | 12.1.3.0.0 | All | All | All |
| Application | Oracle | Service Architecture Leveraging Tuxedo | 12.2.2.0.0 | All | All | All |
| Application | Oracle | Tape Library Acsls | 8.4 | All | All | All |
| Application | Oracle | Tape Library Acsls | 8.4 | All | All | All |
| Application | Oracle | Weblogic Server | 10.3.6.0 | All | All | All |
| Application | Oracle | Weblogic Server | 12.1.3.0 | All | All | All |
| Application | Oracle | Weblogic Server | 12.2.1.2 | All | All | All |
| Application | Oracle | Weblogic Server | 12.2.1.3 | All | All | All |
| Application | Oracle | Weblogic Server | 10.3.6.0 | All | All | All |
| Application | Oracle | Weblogic Server | 12.1.3.0 | All | All | All |
| Application | Oracle | Weblogic Server | 12.2.1.2 | All | All | All |
| Application | Oracle | Weblogic Server | 12.2.1.3 | All | All | All |
| Application | Pivotal Software | Spring Framework | 5.0.5 | All | All | All |
| Application | Pivotal Software | Spring Framework | 5.0.5 | All | All | All |
| Application | Pivotal Software | Spring Security | All | All | All | All |
| Application | Pivotal Software | Spring Security | All | All | All | All |
| Application | Redhat | Fuse | 7.3.0 | All | All | All |
| Application | Vmware | Spring Framework | 5.0.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle Critical Patch Update Advisory - July 2020 | MISC | www.oracle.com | |
| Spring Security and Spring Framework CVE-2018-1258 Authorization Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CPU July 2018 | CONFIRM | www.oracle.com | Patch, Third Party Advisory |
| CVE-2018-1258: Unauthorized Access with Spring Security Method Security | Security | Pivotal | CONFIRM | pivotal.io | Vendor Advisory |
| MySQL Multiple Flaws Let Remote Users Gain Elevated Privileges, Remote Authenticated Users Access and Modify Data, and Remote and Local Users Deny Service - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Oracle Critical Patch Update Advisory - October 2021 | MISC | www.oracle.com | |
| Oracle Critical Patch Update - January 2019 | CONFIRM | www.oracle.com | Patch, Third Party Advisory |
| Oracle Critical Patch Update - July 2019 | MISC | www.oracle.com | |
| October 2018 MySQL Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| CPU Oct 2018 | CONFIRM | www.oracle.com | Patch, Third Party Advisory |
| Oracle Critical Patch Update Advisory - January 2020 | MISC | www.oracle.com | |
| Oracle Critical Patch Update Advisory - April 2020 | N/A | www.oracle.com | |
| Oracle WebLogic Server Multiple Bugs Let Remote Users Gain Elevated Privileges, Access Data, and Partially Modify Data - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Oracle Critical Patch Update Advisory - January 2021 | MISC | www.oracle.com | |
| Oracle Critical Patch Update Advisory - April 2019 | MISC | www.oracle.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980285 Java (maven) Security Update for org.springframework:spring-core (GHSA-cxrj-66c5-9fmh)