cbcvebase.
CVE-2018-11039
published 2018-06-25

CVE-2018-11039: Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP…

medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

Affected

67 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibspring-java< libspring-java 4.3.19-1 (bookworm)libspring-java 4.3.19-1 (bookworm)
oracleagile_plm
oracleagile_plm
oracleagile_plm
oracleagile_plm
oracleapplication_testing_suite
oracleapplication_testing_suite
oracleapplication_testing_suite
oracleapplication_testing_suite
oraclecommunications_diameter_signaling_router< 8.38.3
oraclecommunications_network_integrity7.3.2 – 7.3.6
oraclecommunications_online_mediation_controller
oraclecommunications_performance_intelligence_center< 10.2.110.2.1
oraclecommunications_services_gatekeeper< 6.1.0.4.06.1.0.4.0
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oracleendeca_information_discovery_integrator
oracleendeca_information_discovery_integrator
oracleenterprise_manager_base_platform
oracleenterprise_manager_base_platform
oracleenterprise_manager_base_platform
oracleenterprise_manager_for_mysql_database

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM