Missing authorization in Spring Framework - CVE-2018-1258
Published: May 15, 2018 / Updated: May 15, 2018
Vulnerability identifier: #VU12651
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1258
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to bypass security restrictions on the target system.
The weakness exists due to improper security restrictions when using Spring Security method security. A remote attacker can submit a specially crafted request, bypass authorization restrictions and gain unauthorized access to certain methods that should be restricted.
The weakness exists due to improper security restrictions when using Spring Security method security. A remote attacker can submit a specially crafted request, bypass authorization restrictions and gain unauthorized access to certain methods that should be restricted.
Affected software
Spring Framework
Oracle Healthcare Master Person Index
Oracle Insurance Rules Palette
Oracle Application Testing Suite
Oracle Retail Customer Insights
Oracle Retail Service Backbone
Oracle Health Sciences Information Manager
Oracle Communications Services Gatekeeper
Fuse
Oracle Retail Predictive Application Server
Oracle Communications Diameter Signaling Router (DSR)
Oracle Communications Performance Intelligence Center (PIC) Software
Oracle Insurance Calculation Engine
Oracle Healthcare Master Person Index
Oracle Insurance Rules Palette
Oracle Application Testing Suite
Oracle Retail Customer Insights
Oracle Retail Service Backbone
Oracle Health Sciences Information Manager
Oracle Communications Services Gatekeeper
Fuse
Oracle Retail Predictive Application Server
Oracle Communications Diameter Signaling Router (DSR)
Oracle Communications Performance Intelligence Center (PIC) Software
Oracle Insurance Calculation Engine
How to mitigate CVE-2018-1258
Update to version 5.0.6.
Oracle Communications Services Gatekeeper - update to 6.1.0.4.0
Fuse - update to 7.4.0
Oracle Communications Performance Intelligence Center (PIC) Software - update to 10.2.1
Fuse - update to 7.4.0
Oracle Communications Performance Intelligence Center (PIC) Software - update to 10.2.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Pivotal Spring Framework
- Multiple vulnerabilities in Oracle Insurance Applications
- Multiple vulnerabilities in Red Hat Fuse
- Missing authorization in Oracle Retail Service Backbone
- Missing authorization in Oracle Retail Predictive Application Server
- Multiple vulnerabilities in Oracle Retail Customer Insights
- Missing authorization in Oracle Insurance Calculation Engine
- Missing authorization in Oracle Insurance Rules Palette
- Missing authorization in Oracle Health Sciences Information Manager
- Missing authorization in Oracle Healthcare Master Person Index
- Multiple vulnerabilities in Oracle Application Testing Suite
- Multiple vulnerabilities in Oracle Communications Services Gatekeeper
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router (DSR)
- Missing authorization in Oracle Communications Performance Intelligence Center (PIC) Software