CVE-2018-1271
Summary
| CVE | CVE-2018-1271 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-06 13:29:00 UTC |
| Updated | 2022-06-23 16:33:00 UTC |
| Description | Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Application Testing Suite | 12.5.0.3 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.1.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.2.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.3.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 12.5.0.3 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.1.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.2.0.1 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.3.0.1 | All | All | All |
| Application | Oracle | Big Data Discovery | 1.6.0 | All | All | All |
| Application | Oracle | Big Data Discovery | 1.6.0 | All | All | All |
| Application | Oracle | Communications Converged Application Server | All | All | All | All |
| Application | Oracle | Communications Converged Application Server | All | All | All | All |
| Application | Oracle | Communications Diameter Signaling Router | All | All | All | All |
| Application | Oracle | Communications Diameter Signaling Router | All | All | All | All |
| Application | Oracle | Communications Performance Intelligence Center | All | All | All | All |
| Application | Oracle | Communications Performance Intelligence Center | All | All | All | All |
| Application | Oracle | Communications Policy Management | 12.5.0 | All | All | All |
| Application | Oracle | Communications Services Gatekeeper | All | All | All | All |
| Application | Oracle | Communications Services Gatekeeper | All | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.2.2 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.3.3 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.2.2 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.3.3 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.2.0.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.3.1.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.3.2.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.2.0.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.3.1.1 | All | All | All |
| Application | Oracle | Goldengate For Big Data | 12.3.2.1 | All | All | All |
| Application | Oracle | Healthcare Master Person Index | 3.0 | All | All | All |
| Application | Oracle | Healthcare Master Person Index | 4.0 | All | All | All |
| Application | Oracle | Healthcare Master Person Index | 3.0 | All | All | All |
| Application | Oracle | Healthcare Master Person Index | 4.0 | All | All | All |
| Application | Oracle | Health Sciences Information Manager | 3.0 | All | All | All |
| Application | Oracle | Health Sciences Information Manager | 3.0 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.1.1 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.2 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.2.1 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.1.1 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.2 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | 10.2.1 | All | All | All |
| Application | Oracle | Insurance Calculation Engine | All | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.1 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.2 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.1 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.1 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 10.2 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.1 | All | All | All |
| Application | Oracle | Primavera Gateway | 15.2 | All | All | All |
| Application | Oracle | Primavera Gateway | 16.2 | All | All | All |
| Application | Oracle | Primavera Gateway | 17.12 | All | All | All |
| Application | Oracle | Primavera Gateway | 15.2 | All | All | All |
| Application | Oracle | Primavera Gateway | 16.2 | All | All | All |
| Application | Oracle | Primavera Gateway | 17.12 | All | All | All |
| Application | Oracle | Rapid Planning | 12.1 | All | All | All |
| Application | Oracle | Rapid Planning | 12.2 | All | All | All |
| Application | Oracle | Retail Back Office | 14.0 | All | All | All |
| Application | Oracle | Retail Back Office | 14.1 | All | All | All |
| Application | Oracle | Retail Back Office | 14.0 | All | All | All |
| Application | Oracle | Retail Back Office | 14.1 | All | All | All |
| Application | Oracle | Retail Central Office | 14.0 | All | All | All |
| Application | Oracle | Retail Central Office | 14.1 | All | All | All |
| Application | Oracle | Retail Central Office | 14.0 | All | All | All |
| Application | Oracle | Retail Central Office | 14.1 | All | All | All |
| Application | Oracle | Retail Customer Insights | 15.0 | All | All | All |
| Application | Oracle | Retail Customer Insights | 16.0 | All | All | All |
| Application | Oracle | Retail Customer Insights | 15.0 | All | All | All |
| Application | Oracle | Retail Customer Insights | 16.0 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.0.2 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.0.3 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.0.4 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.2 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.3 | All | All | All |
| Application | Oracle | Retail Integration Bus | 15.0.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 15.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 15.0.2 | All | All | All |
| Application | Oracle | Retail Integration Bus | 16.0 | All | All | All |
| Application | Oracle | Retail Integration Bus | 16.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 16.0.2 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.0.2 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.0.3 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.0.4 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.2 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.3 | All | All | All |
| Application | Oracle | Retail Integration Bus | 15.0.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 15.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 15.0.2 | All | All | All |
| Application | Oracle | Retail Integration Bus | 16.0 | All | All | All |
| Application | Oracle | Retail Integration Bus | 16.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 16.0.2 | All | All | All |
| Application | Oracle | Retail Open Commerce Platform | 5.3.0 | All | All | All |
| Application | Oracle | Retail Open Commerce Platform | 6.0.0 | All | All | All |
| Application | Oracle | Retail Open Commerce Platform | 6.0.1 | All | All | All |
| Application | Oracle | Retail Open Commerce Platform | 5.3.0 | All | All | All |
| Application | Oracle | Retail Open Commerce Platform | 6.0.0 | All | All | All |
| Application | Oracle | Retail Open Commerce Platform | 6.0.1 | All | All | All |
| Application | Oracle | Retail Order Broker | 15.0 | All | All | All |
| Application | Oracle | Retail Order Broker | 16.0 | All | All | All |
| Application | Oracle | Retail Order Broker | 5.1 | All | All | All |
| Application | Oracle | Retail Order Broker | 5.2 | All | All | All |
| Application | Oracle | Retail Order Broker | 15.0 | All | All | All |
| Application | Oracle | Retail Order Broker | 16.0 | All | All | All |
| Application | Oracle | Retail Order Broker | 5.1 | All | All | All |
| Application | Oracle | Retail Order Broker | 5.2 | All | All | All |
| Application | Oracle | Retail Point-of-sale | 14.0 | All | All | All |
| Application | Oracle | Retail Point-of-sale | 14.1 | All | All | All |
| Application | Oracle | Retail Point-of-sale | 14.0 | All | All | All |
| Application | Oracle | Retail Point-of-sale | 14.1 | All | All | All |
| Application | Oracle | Retail Predictive Application Server | 14.0 | All | All | All |
| Application | Oracle | Retail Predictive Application Server | 14.1 | All | All | All |
| Application | Oracle | Retail Predictive Application Server | 15.0 | All | All | All |
| Application | Oracle | Retail Predictive Application Server | 16.0 | All | All | All |
| Application | Oracle | Retail Predictive Application Server | 14.0 | All | All | All |
| Application | Oracle | Retail Predictive Application Server | 14.1 | All | All | All |
| Application | Oracle | Retail Predictive Application Server | 15.0 | All | All | All |
| Application | Oracle | Retail Predictive Application Server | 16.0 | All | All | All |
| Application | Oracle | Retail Returns Management | 14.0 | All | All | All |
| Application | Oracle | Retail Returns Management | 14.1 | All | All | All |
| Application | Oracle | Retail Returns Management | 14.0 | All | All | All |
| Application | Oracle | Retail Returns Management | 14.1 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 7.1 | All | All | All |
| Application | Oracle | Service Architecture Leveraging Tuxedo | 12.1.3.0.0 | All | All | All |
| Application | Oracle | Service Architecture Leveraging Tuxedo | 12.2.2.0.0 | All | All | All |
| Application | Oracle | Service Architecture Leveraging Tuxedo | 12.1.3.0.0 | All | All | All |
| Application | Oracle | Service Architecture Leveraging Tuxedo | 12.2.2.0.0 | All | All | All |
| Application | Oracle | Tape Library Acsls | 8.4 | All | All | All |
| Application | Oracle | Tape Library Acsls | 8.4 | All | All | All |
| Application | Pivotal Software | Spring Framework | All | All | All | All |
| Application | Pivotal Software | Spring Framework | All | All | All | All |
| Application | Pivotal Software | Spring Framework | All | All | All | All |
| Application | Vmware | Spring Framework | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pivotal Spring Framework CVE-2018-1271 Directory Traversal Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| Oracle Critical Patch Update Advisory - July 2020 | MISC | www.oracle.com | |
| CPU July 2018 | CONFIRM | www.oracle.com | Patch |
| Oracle Critical Patch Update Advisory - October 2021 | MISC | www.oracle.com | |
| Oracle Critical Patch Update - January 2019 | CONFIRM | www.oracle.com | Patch |
| CVE-2018-1271: Directory Traversal with Spring MVC on Windows | Security | Pivotal | CONFIRM | pivotal.io | Vendor Advisory |
| Oracle Critical Patch Update - July 2019 | MISC | www.oracle.com | |
| CPU Oct 2018 | CONFIRM | www.oracle.com | Patch |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980281 Java (maven) Security Update for org.springframework:spring-core (GHSA-g8hw-794c-4j9g)