cbcvebase.
CVE-2018-1258
published 2018-05-11

CVE-2018-1258: Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.

Affected

77 ranges· showing 25
VendorProductVersion rangeFixed in
netapponcommand_unified_manager>= 7.3
netapponcommand_unified_manager>= 9.4
oracleagile_plm
oracleagile_plm
oracleagile_plm
oracleagile_plm
oracleapplication_testing_suite
oracleapplication_testing_suite
oracleapplication_testing_suite
oracleapplication_testing_suite
oracleapplication_testing_suite
oraclebig_data_discovery
oraclecommunications_converged_application_server< 7.0.0.17.0.0.1
oraclecommunications_diameter_signaling_router< 8.38.3
oraclecommunications_network_integrity7.3.2 – 7.3.6
oraclecommunications_performance_intelligence_center< 10.2.110.2.1
oraclecommunications_services_gatekeeper< 6.1.0.4.06.1.0.4.0
oracleendeca_information_discovery_integrator
oracleendeca_information_discovery_integrator
oracleenterprise_manager_for_mysql_database
oracleenterprise_manager_ops_center
oracleenterprise_manager_ops_center
oracleenterprise_repository
oracleenterprise_repository
oraclegoldengate_for_big_data