CVE-2018-1258
Summary
| CVE | CVE-2018-1258 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-11 20:29:00 UTC |
| Updated | 2026-08-25 16:28:27 UTC |
| Description | Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.024570000 probability, percentile 0.831930000 (date 2026-08-25)
Problem Types: CWE-863 | Authorization Bypass
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 6.5 | AV:N/AC:L/Au:S/C:P/I:P/A:P |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Netapp | Oncommand Insight | - | All | All | All |
| Application | Netapp | Oncommand Unified Manager | All | All | All | All |
| Application | Netapp | Oncommand Unified Manager | All | All | All | All |
| Application | Netapp | Oncommand Workflow Automation | - | All | All | All |
| Application | Netapp | Snapcenter | - | All | All | All |
| Application | Netapp | Storage Automation Store | - | All | All | All |
| Application | Oracle | Agile Product Lifecycle Management | 9.3.3 | All | All | All |
| Application | Oracle | Agile Product Lifecycle Management | 9.3.4 | All | All | All |
| Application | Oracle | Agile Product Lifecycle Management | 9.3.5 | All | All | All |
| Application | Oracle | Agile Product Lifecycle Management | 9.3.6 | All | All | All |
| Application | Oracle | Application Testing Suite | 10.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 12.5.0.3 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.1.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.2.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.3.0.1 | All | All | All |
| Application | Oracle | Big Data Discovery | 1.6.0 | All | All | All |
| Application | Oracle | Communications Converged Application Server | All | All | All | All |
| Application | Oracle | Communications Diameter Signaling Router | All | All | All | All |
| Application | Oracle | Communications Network Integrity | All | All | All | All |
| Application | Oracle | Communications Performance Intelligence Center | All | All | All | All |
| Application | Oracle | Communications Services Gatekeeper | All | All | All | All |
| Application | Oracle | Endeca Information Discovery Integrator | 3.1.0 | All | All | All |
| Application | Oracle | Endeca Information Discovery Integrator | 3.2.0 | All | All | All |
| Application | Oracle | Enterprise Manager For Mysql Database | 13.2 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.2.2 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.3.3 | All | All | All |
| Application | Oracle | Enterprise Repository | 11.1.1.7.0 | All | All | All |
| Application | Oracle | Enterprise Repository | 12.1.3.0.0 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.2.0.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.3.1.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.3.2.1 | All | All | All |
| Application | Oracle | Healthcare Master Person Index | 3.0 | All | All | All |
| Application | Oracle | Healthcare Master Person Index | 4.0 | All | All | All |
| Application | Oracle | Health Sciences Information Manager | 3.0 | All | All | All |
| Application | Oracle | Hospitality Guest Access | 4.2.0 | All | All | All |
| Application | Oracle | Hospitality Guest Access | 4.2.1 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.1.1 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.2 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.2.1 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 10.0 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 10.1 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 10.2 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 11.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.1 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.2 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.1 | All | All | All |
| Application | Oracle | Micros Lucas | 2.9.5 | All | All | All |
| Application | Oracle | Mysql Enterprise Monitor | All | All | All | All |
| Application | Oracle | Peoplesoft Enterprise Fin Install | 9.2 | All | All | All |
| Application | Oracle | Retail Assortment Planning | 14.1 | All | All | All |
| Application | Oracle | Retail Assortment Planning | 15.0 | All | All | All |
| Application | Oracle | Retail Assortment Planning | 16.0 | All | All | All |
| Application | Oracle | Retail Back Office | 14.0 | All | All | All |
| Application | Oracle | Retail Back Office | 14.1 | All | All | All |
| Application | Oracle | Retail Central Office | 14.0 | All | All | All |
| Application | Oracle | Retail Central Office | 14.1 | All | All | All |
| Application | Oracle | Retail Customer Insights | 15.0 | All | All | All |
| Application | Oracle | Retail Customer Insights | 16.0 | All | All | All |
| Application | Oracle | Retail Financial Integration | 13.2 | All | All | All |
| Application | Oracle | Retail Financial Integration | 14.0 | All | All | All |
| Application | Oracle | Retail Financial Integration | 14.1 | All | All | All |
| Application | Oracle | Retail Financial Integration | 15.0 | All | All | All |
| Application | Oracle | Retail Financial Integration | 16.0 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.2 | All | All | All |
| Application | Oracle | Retail Point-of-service | 14.0 | All | All | All |
| Application | Oracle | Retail Point-of-service | 14.1 | All | All | All |
| Application | Oracle | Retail Returns Management | 14.0 | All | All | All |
| Application | Oracle | Retail Returns Management | 14.1 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 17.0 | All | All | All |
| Application | Oracle | Service Architecture Leveraging Tuxedo | 12.1.3.0.0 | All | All | All |
| Application | Oracle | Service Architecture Leveraging Tuxedo | 12.2.2.0.0 | All | All | All |
| Application | Oracle | Tape Library Acsls | 8.4 | All | All | All |
| Application | Oracle | Weblogic Server | 10.3.6.0 | All | All | All |
| Application | Oracle | Weblogic Server | 12.1.3.0 | All | All | All |
| Application | Oracle | Weblogic Server | 12.2.1.2 | All | All | All |
| Application | Oracle | Weblogic Server | 12.2.1.3 | All | All | All |
| Application | Pivotal Software | Spring Security | All | All | All | All |
| Application | Redhat | Fuse | 7.3.0 | All | All | All |
| Application | Vmware | Spring Framework | 5.0.5 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Pivotal | Spring Framework | affected 5.0.5 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CPU Oct 2018 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Oracle Critical Patch Update Advisory - October 2021 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Oracle Critical Patch Update - July 2019 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Oracle Critical Patch Update Advisory - January 2021 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Oracle Critical Patch Update - January 2019 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| CVE-2018-1258: Unauthorized Access with Spring Security Method Security | Security | Pivotal | af854a3a-2127-422b-91ae-364da2661108 | pivotal.io | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Patch, Third Party Advisory |
| Oracle Critical Patch Update Advisory - April 2020 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Spring Security and Spring Framework CVE-2018-1258 Authorization Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Oracle WebLogic Server Multiple Bugs Let Remote Users Gain Elevated Privileges, Access Data, and Partially Modify Data - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Oracle Critical Patch Update Advisory - April 2019 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| October 2018 MySQL Vulnerabilities in NetApp Products | NetApp Product Security | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | Third Party Advisory |
| CPU July 2018 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| MySQL Multiple Flaws Let Remote Users Gain Elevated Privileges, Remote Authenticated Users Access and Modify Data, and Remote and Local Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Oracle Critical Patch Update Advisory - January 2020 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Oracle Critical Patch Update Advisory - July 2020 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980285 Java (maven) Security Update for org.springframework:spring-core (GHSA-cxrj-66c5-9fmh)