Improper privilege management in Spring Framework - CVE-2018-1272

 

Improper privilege management in Spring Framework - CVE-2018-1272

Published: April 11, 2018


Vulnerability identifier: #VU11753
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1272
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to gain elevated privileges on the target system.

The weakness exists due to improper processing of multipart requests. A remote attacker can make a multipart request that injects malicious content to the target server, cause it to use wrong values and gain root privileges.


Affected software

Spring Framework
watsonx.data
Dell Support Assist Enterprise
Storage Copy Data Management
MobileFirst Platform
IBM Engineering Requirements Management DOORS Next
Fuse
IBM Cognos Controller

How to mitigate CVE-2018-1272

Update to versions 5.0.5 or 4.3.15.

watsonx.data - update to 2.1
Dell Support Assist Enterprise - update to 4.00.06.00
Storage Copy Data Management - update to 2.2.26.0
Fuse - update to 7.1.0
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2

External References

Related Security Bulletins