Improper input validation in Spring Framework - CVE-2018-15756

 

Improper input validation in Spring Framework - CVE-2018-15756

Published: October 22, 2018 / Updated: October 23, 2018


Vulnerability identifier: #VU15467
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15756
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists in Pivotal Software Spring Framework due to improper handling of range requests. A remote attacker can send a specially crafted request that contains an additional range header with a high number of ranges or with wide ranges that overlap and cause the service to crash.


Affected software

Spring Framework
Oracle Healthcare Master Person Index
Dell Support Assist Enterprise
Oracle Communications Online Mediation Controller
Oracle Financial Services Analytical Applications Infrastructure
Oracle Insurance Rules Palette
Oracle FLEXCUBE Private Banking
IBM Engineering Requirements Management DOORS Next
Oracle Endeca Information Discovery Integrator
Oracle Communications Session Route Manager
Identity Manager Connector
Oracle Insurance Policy Administration
Oracle WebCenter Sites
Primavera Analytics
MySQL Enterprise Monitor
Fuse
Oracle WebLogic Server
Primavera Gateway
AMQ Broker
Oracle Communications Unified Inventory Management
Oracle Communications Diameter Signaling Router (DSR)
Oracle Communications Session Report Manager
Autodesk Infraworks
Tape Library ACSLS
Oracle Agile PLM Framework
Oracle Insurance Calculation Engine
Oracle GoldenGate Application Adapters
Enterprise Manager for Fusion Applications
Oracle Retail Financial Integration
Oracle Retail Advanced Inventory Planning
Oracle Retail Integration Bus

How to mitigate CVE-2018-15756

The vulnerability has been addressed in the version 4.3.20, 5.0.10, 5.1.1.

Spring Framework - addressed in versions 4.3.20, 5.0.10, 5.1.1
MySQL Enterprise Monitor - addressed in versions 4.0.10, 8.0.16
Dell Support Assist Enterprise - update to 4.00.06.00
Fuse - update to 7.6.0
Oracle Financial Services Analytical Applications Infrastructure - update to 8.0.8.0
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
AMQ Broker - update to 7.4.4
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7

External References

Related Security Bulletins