CVE-2018-1273
Summary
| CVE | CVE-2018-1273 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-11 13:29:00 UTC |
| Updated | 2026-06-26 18:44:14 UTC |
| Description | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.956490000 probability, percentile 0.998610000 (date 2026-06-25)
CISA KEV: Listed on 2022-03-25; due 2022-04-15; ransomware use Known
Problem Types: CWE-94 | NVD-CWE-Other | CWE-94 CWE-94 - Code Injection
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
CISA Known Exploited Vulnerability
| Vendor | VMware Tanzu |
|---|---|
| Product | Spring Data Commons |
| Name | VMware Tanzu Spring Data Commons Property Binder Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2018-1273 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Ignite | 1.0.0 | - | All | All |
| Application | Apache | Ignite | 1.0.0 | rc3 | All | All |
| Application | Apache | Ignite | All | All | All | All |
| Application | Broadcom | Spring Data Commons | All | All | All | All |
| Application | Broadcom | Spring Data Commons | All | All | All | All |
| Application | Broadcom | Spring Data Commons | All | All | All | All |
| Application | Oracle | Financial Services Crime And Compliance Management Studio | 8.0.8.2.0 | All | All | All |
| Application | Oracle | Financial Services Crime And Compliance Management Studio | 8.0.8.3.0 | All | All | All |
| Application | Pivotal Software | Spring Data Rest | All | All | All | All |
| Application | Vmware | Spring Data Rest | All | All | All | All |
| Application | Vmware | Spring Data Rest | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Spring By Pivotal | Spring Framework | affected Versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle Critical Patch Update Advisory - July 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| [CVE-2018-1273] Apache Ignite impacted by security vulnerability in Spring Data Commons | af854a3a-2127-422b-91ae-364da2661108 | mail-archives.apache.org | Mailing List, Third Party Advisory |
| CVE-2018-1273: RCE with Spring Data Commons | Security | VMware Tanzu | af854a3a-2127-422b-91ae-364da2661108 | pivotal.io | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2022-03-25T00:00:00.000Z | CVE-2018-1273 added to CISA KEV |
Legacy QID Mappings
- 983145 Java (maven) Security Update for org.springframework.data:spring-data-commons (GHSA-4fq3-mr56-cg6r)