CVE-2018-1273

CVE Published 2018-04-11
Related CWE(s) CWE-20: Improper Input Validation, CWE-94: Improper Control of Generation of Code ('Code Injection'), CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Related Vendor(s) pivotal_software, oracle, apache
Related Product(s) financial_services_crime_and_compliance_management_studio, spring_data_rest, ignite, spring_data_commons
Exploitation Reported (CISA KEV) 2022-03-25
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References