imPC@ndo IT

Tracker / CVE-2018-1272

CVE-2018-1272

High 7.5

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

Affected products and versions

oracle application_testing_suite
oracle big_data_discovery
oracle communications_converged_application_server · … → 7.0.0.1
oracle communications_diameter_signaling_router · … → 8.3
oracle communications_performance_intelligence_center · … → 10.2.1
oracle communications_services_gatekeeper · … → 6.1.0.4.0
oracle enterprise_manager_ops_center
oracle goldengate_for_big_data
oracle health_sciences_information_manager
oracle healthcare_master_person_index
oracle insurance_calculation_engine
oracle insurance_rules_palette
oracle primavera_gateway
oracle retail_back_office
oracle retail_central_office
oracle retail_customer_insights
oracle retail_integration_bus
oracle retail_open_commerce_platform
oracle retail_order_broker
oracle retail_point-of-sale
oracle retail_predictive_application_server
oracle retail_returns_management
oracle service_architecture_leveraging_tuxedo
oracle tape_library_acsls
vmware spring_framework · 4.3.0 → 4.3.15
vmware spring_framework · 5.0 → 5.0.5

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References