Path traversal in Spring Framework - CVE-2018-1271
Published: April 11, 2018 / Updated: April 11, 2018
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to obtain potentially sensitive information and write arbitrary files on the target system.
The weakness exists in the spring-webmvc module due to the improper serving of static resources from a file system on Microsoft Windows systems. A remote attacker can send a malicious request using a crafted URL, trigger directory traversal, overwrite, delete or read potentially sensitive file information.
Affected software
Dell Support Assist Enterprise
IBM Engineering Requirements Management DOORS Next
Fuse
IBM Cognos Controller
How to mitigate CVE-2018-1271
Fuse - update to 7.1.0
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2