Improper input validation in Spring Framework - CVE-2018-1275

 

Improper input validation in Spring Framework - CVE-2018-1275

Published: April 24, 2018


Vulnerability identifier: #VU12131
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1275
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to allowing applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A remote attacker can submit a sepcially crafted message to the broker and execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

Spring Framework
Dell Support Assist Enterprise
Oracle Insurance Rules Palette
Oracle Communications Converged Application Server - Service Controller
Tape Library ACSLS
Oracle Insurance Calculation Engine
Oracle Service Architecture Leveraging Tuxedo
IBM Cognos Controller

How to mitigate CVE-2018-1275

Update to versions 5.0.5 or 4.3.16.

Dell Support Assist Enterprise - update to 4.00.06.00
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2

External References

Related Security Bulletins