CVE-2018-1273

CVE Published 2018-04-11
Related CWE(s) CWE-20: Improper Input Validation, CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), CWE-94: Improper Control of Generation of Code ('Code Injection')
Related Vendor(s) apache, pivotal_software, oracle
Related Product(s) financial_services_crime_and_compliance_management_studio, spring_data_commons, ignite, spring_data_rest
Exploitation Reported (CISA KEV) 2022-03-25
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References