CVE-2018-1270
Summary
| CVE | CVE-2018-1270 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-06 13:29:00 UTC |
| Updated | 2023-11-07 02:55:00 UTC |
| Description | Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Oracle | Application Testing Suite | 12.5.0.3 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.1.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.2.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.3.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 12.5.0.3 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.1.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.2.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.3.0.1 | All | All | All |
| Application | Oracle | Big Data Discovery | 1.6.0 | All | All | All |
| Application | Oracle | Big Data Discovery | 1.6.0 | All | All | All |
| Application | Oracle | Communications Converged Application Server | All | All | All | All |
| Application | Oracle | Communications Converged Application Server | All | All | All | All |
| Application | Oracle | Communications Diameter Signaling Router | All | All | All | All |
| Application | Oracle | Communications Diameter Signaling Router | All | All | All | All |
| Application | Oracle | Communications Performance Intelligence Center | All | All | All | All |
| Application | Oracle | Communications Performance Intelligence Center | All | All | All | All |
| Application | Oracle | Communications Services Gatekeeper | All | All | All | All |
| Application | Oracle | Communications Services Gatekeeper | All | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.2.2 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.3.3 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.2.2 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.3.3 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.2.0.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.3.1.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.3.2.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.2.0.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.3.1.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.3.2.1 | All | All | All |
| Application | Oracle | Healthcare Master Person Index | 3.0 | All | All | All |
| Application | Oracle | Healthcare Master Person Index | 4.0 | All | All | All |
| Application | Oracle | Healthcare Master Person Index | 3.0 | All | All | All |
| Application | Oracle | Healthcare Master Person Index | 4.0 | All | All | All |
| Application | Oracle | Health Sciences Information Manager | 3.0 | All | All | All |
| Application | Oracle | Health Sciences Information Manager | 3.0 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.1.1 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.2 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.2.1 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.1.1 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.2 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.2.1 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.1 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.2 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.1 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.1 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.2 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.1 | All | All | All |
| Application | Oracle | Primavera Gateway | 15.2 | All | All | All |
| Application | Oracle | Primavera Gateway | 16.2 | All | All | All |
| Application | Oracle | Primavera Gateway | 17.12 | All | All | All |
| Application | Oracle | Primavera Gateway | 15.2 | All | All | All |
| Application | Oracle | Primavera Gateway | 16.2 | All | All | All |
| Application | Oracle | Primavera Gateway | 17.12 | All | All | All |
| Application | Oracle | Retail Back Office | 14.0 | All | All | All |
| Application | Oracle | Retail Back Office | 14.1 | All | All | All |
| Application | Oracle | Retail Back Office | 14.0 | All | All | All |
| Application | Oracle | Retail Back Office | 14.1 | All | All | All |
| Application | Oracle | Retail Central Office | 14.0 | All | All | All |
| Application | Oracle | Retail Central Office | 14.1 | All | All | All |
| Application | Oracle | Retail Central Office | 14.0 | All | All | All |
| Application | Oracle | Retail Central Office | 14.1 | All | All | All |
| Application | Oracle | Retail Customer Insights | 15.0 | All | All | All |
| Application | Oracle | Retail Customer Insights | 16.0 | All | All | All |
| Application | Oracle | Retail Customer Insights | 15.0 | All | All | All |
| Application | Oracle | Retail Customer Insights | 16.0 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.0.2 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.0.3 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.0.4 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.2 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.3 | All | All | All |
| Application | Oracle | Retail Integration Bus | 15.0.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 15.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 15.0.2 | All | All | All |
| Application | Oracle | Retail Integration Bus | 16.0 | All | All | All |
| Application | Oracle | Retail Integration Bus | 16.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 16.0.2 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.0.2 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.0.3 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.0.4 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.2 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.3 | All | All | All |
| Application | Oracle | Retail Integration Bus | 15.0.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 15.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 15.0.2 | All | All | All |
| Application | Oracle | Retail Integration Bus | 16.0 | All | All | All |
| Application | Oracle | Retail Integration Bus | 16.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 16.0.2 | All | All | All |
| Application | Oracle | Retail Open Commerce Platform | 5.3.0 | All | All | All |
| Application | Oracle | Retail Open Commerce Platform | 6.0.0 | All | All | All |
| Application | Oracle | Retail Open Commerce Platform | 6.0.1 | All | All | All |
| Application | Oracle | Retail Open Commerce Platform | 5.3.0 | All | All | All |
| Application | Oracle | Retail Open Commerce Platform | 6.0.0 | All | All | All |
| Application | Oracle | Retail Open Commerce Platform | 6.0.1 | All | All | All |
| Application | Oracle | Retail Order Broker | 15.0 | All | All | All |
| Application | Oracle | Retail Order Broker | 16.0 | All | All | All |
| Application | Oracle | Retail Order Broker | 5.1 | All | All | All |
| Application | Oracle | Retail Order Broker | 5.2 | All | All | All |
| Application | Oracle | Retail Order Broker | 15.0 | All | All | All |
| Application | Oracle | Retail Order Broker | 16.0 | All | All | All |
| Application | Oracle | Retail Order Broker | 5.1 | All | All | All |
| Application | Oracle | Retail Order Broker | 5.2 | All | All | All |
| Application | Oracle | Retail Point-of-sale | 14.0 | All | All | All |
| Application | Oracle | Retail Point-of-sale | 14.1 | All | All | All |
| Application | Oracle | Retail Point-of-sale | 14.0 | All | All | All |
| Application | Oracle | Retail Point-of-sale | 14.1 | All | All | All |
| Application | Oracle | Retail Predictive Application Server | 14.0 | All | All | All |
| Application | Oracle | Retail Predictive Application Server | 14.1 | All | All | All |
| Application | Oracle | Retail Predictive Application Server | 15.0 | All | All | All |
| Application | Oracle | Retail Predictive Application Server | 16.0 | All | All | All |
| Application | Oracle | Retail Predictive Application Server | 14.0 | All | All | All |
| Application | Oracle | Retail Predictive Application Server | 14.1 | All | All | All |
| Application | Oracle | Retail Predictive Application Server | 15.0 | All | All | All |
| Application | Oracle | Retail Predictive Application Server | 16.0 | All | All | All |
| Application | Oracle | Retail Returns Management | 14.0 | All | All | All |
| Application | Oracle | Retail Returns Management | 14.1 | All | All | All |
| Application | Oracle | Retail Returns Management | 14.0 | All | All | All |
| Application | Oracle | Retail Returns Management | 14.1 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 7.1 | All | All | All |
| Application | Oracle | Service Architecture Leveraging Tuxedo | 12.1.3.0.0 | All | All | All |
| Application | Oracle | Service Architecture Leveraging Tuxedo | 12.2.2.0.0 | All | All | All |
| Application | Oracle | Service Architecture Leveraging Tuxedo | 12.1.3.0.0 | All | All | All |
| Application | Oracle | Service Architecture Leveraging Tuxedo | 12.2.2.0.0 | All | All | All |
| Application | Oracle | Tape Library Acsls | 8.4 | All | All | All |
| Application | Oracle | Tape Library Acsls | 8.4 | All | All | All |
| Application | Pivotal Software | Spring Framework | All | All | All | All |
| Application | Pivotal Software | Spring Framework | All | All | All | All |
| Application | Pivotal Software | Spring Framework | All | All | All | All |
| Application | Pivotal Software | Spring Framework | All | All | All | All |
| Application | Pivotal Software | Spring Framework | All | All | All | All |
| Application | Redhat | Fuse | 1.0.0 | All | All | All |
| Application | Vmware | Spring Framework | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pivotal Spring Framework CVE-2018-1270 Remote Code Execution Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| 404 Page Not Found | Exploit Database | EXPLOIT-DB | www.exploit-db.com | Broken Link |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Oracle Critical Patch Update Advisory - July 2020 | MISC | www.oracle.com | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| CPU July 2018 | CONFIRM | www.oracle.com | Patch |
| Oracle Critical Patch Update Advisory - October 2021 | MISC | www.oracle.com | |
| CVE-2018-1270: Remote Code Execution with spring-messaging | Security | Pivotal | CONFIRM | pivotal.io | Vendor Advisory |
| [SECURITY] [DLA 2635-1] libspring-java security update | MLIST | lists.debian.org | |
| Oracle Critical Patch Update - January 2019 | CONFIRM | www.oracle.com | Patch |
| Oracle Critical Patch Update - July 2019 | MISC | www.oracle.com | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| CPU Oct 2018 | CONFIRM | www.oracle.com | Patch |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.