Information disclosure in Spring Framework - CVE-2018-11040
Published: June 27, 2018
Vulnerability details
The disclosed vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to improper cross-domain protections imposed by the affected software. The software allows web applications to enable cross-domain requests via JSON with Padding (JSONP) through the AbstractJsonpResponseBodyAdvice class for REST controllers and through the MappingJackson2JsonView class for browser requests. A remote attacker can trick the victim into following a link that submits malicious input and access sensitive information.
Affected software
Dell Support Assist Enterprise
IBM Cognos Controller
How to mitigate CVE-2018-11040
Dell Support Assist Enterprise - update to 4.00.06.00
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2