CVE-2018-1273
published 2018-04-11CVE-2018-1273: Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by…
PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
95.65%
99.9th percentile
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ignite | — | — |
| apache | ignite | — | — |
| apache | ignite | 1.0.1 – 2.5.0 | — |
| broadcom | spring_data_commons | <= 1.12.10 | — |
| broadcom | spring_data_commons | 1.13.0 – 1.13.10 | — |
| broadcom | spring_data_commons | 2.0.0 – 2.0.5 | — |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
| pivotal_software | spring_data_rest | 3.0.0 – 3.0.5 | — |
| spring_by_pivotal | spring_framework | — | — |
| vmware | spring_data_rest | <= 2.5.10 | — |
| vmware | spring_data_rest | 2.6.0 – 2.6.10 | — |
Detection & IOCsextracted from sources · hover to see the quote
commandPOST /account HTTP/1.1
Content-Type: application/x-www-form-urlencoded
name[#this.getClass().forName('java.lang.Runtime').getRuntime().exec('{{url_encode(command)}}')]={{to_lower(rand_text_alpha(5))}}
url/account
snort↗
46473
yara
id: CVE-2018-1273 — Nuclei template matching POST /account with name[#this.getClass().forName('java.lang.Runtime').getRuntime().exec(...)] parameter and response regex root:.*:0:0: or \[(font|extension|file)s\]- →Exploit payloads for CVE-2018-1273 are delivered via HTTPS to targeted Spring Data REST endpoints; look for POST requests to /account (or similar Spring Data REST paths) with parameter names containing SpEL expressions such as #this.getClass().forName('java.lang.Runtime').getRuntime().exec(...)
- →The exploits for CVE-2018-1273 are sent, typically via HTTPS, to the targeted systems as part of a multi-exploit UPX-packed ELF dropper that also targets CVE-2018-7600 and CVE-2017-10271 ↗
- →Use Snort rule SID 46473 to detect CVE-2018-1273 exploitation attempts ↗
- →HTTP response body matching regex root:.*:0:0: (Linux /etc/passwd) or \[(font|extension|file)s\] (Windows win.ini) indicates successful RCE via CVE-2018-1273
- →Content-Type: application/x-www-form-urlencoded with SpEL injection in parameter name brackets is the attack vector; monitor for bracket-notation parameter names containing Java reflection calls in POST bodies to Spring Data REST endpoints
- ·Affected versions are Spring Data Commons 1.13.x prior to 1.13.10 and 2.0.x prior to 2.0.5; older unsupported versions are also vulnerable ↗
- ·The Snort rule SID 46473 is subject to change; always refer to the latest Firepower Management Center or Snort.org for the most current rule ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Healthcare Data Repository up to 8.1.3.1 FHIR Server injection (ID 370880)
vuldb·2026-06-15·CVSS 9.8
CVE-2018-1273 [CRITICAL] Oracle Healthcare Data Repository up to 8.1.3.1 FHIR Server injection (ID 370880)
A vulnerability, which was classified as very critical, has been found in Oracle Healthcare Data Repository up to 8.1.3.1. Impacted is an unknown function of the component FHIR Server. Performing a manipulation results in injection.
This vulnerability is identified as CVE-2018-1273. The attack can be initiated remotely. Additionally, an exploit exists.
OSV
Spring Data Commons remote code injection vulnerability
osv·2018-10-17
CVE-2018-1273 [CRITICAL] Spring Data Commons remote code injection vulnerability
Spring Data Commons remote code injection vulnerability
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding that can lead to a remote code execution attack.
GHSA
Spring Data Commons remote code injection vulnerability
ghsa·2018-10-17
CVE-2018-1273 [CRITICAL] CWE-20 Spring Data Commons remote code injection vulnerability
Spring Data Commons remote code injection vulnerability
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding that can lead to a remote code execution attack.
VulnCheck
VMware Tanzu Spring Data Commons Property Binder Vulnerability
vulncheck·2018·CVSS 9.8
CVE-2018-1273 [CRITICAL] CWE-94 VMware Tanzu Spring Data Commons Property Binder Vulnerability
VMware Tanzu Spring Data Commons Property Binder Vulnerability
Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.
Affected: VMware Spring Data Commons
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.lacework.com/blog/elf-of-the-month-new-lucky-ransomware-sample/; https://www.fortinet.com/blog/threat-research/closer-look-satan-ransomwares-propagation-technics; https://web.archive.org/web/20220227045141/https://risksense.com/wp-content/uploads/2019/09/RiskSense-Spotlight-Report-Ransomware.pdf; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://dashboard.shadowserver.org/statistics/honeypot/vuln
Oracle
Oracle Oracle Communications Risk Matrix: Studio (Spring Data Commons) — CVE-2018-1273
vendor_oracle·2023-01-15·CVSS 9.8
CVE-2018-1273 [CRITICAL] Oracle Oracle Communications Risk Matrix: Studio (Spring Data Commons) — CVE-2018-1273
Oracle Oracle Communications Risk Matrix: Studio (Spring Data Commons) vulnerability
CVE: CVE-2018-1273
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Studio (Spring Data Commons) — CVE-2018-1273
vendor_oracle·2022-07-15·CVSS 9.8
CVE-2018-1273 [CRITICAL] Oracle Oracle Financial Services Applications Risk Matrix: Studio (Spring Data Commons) — CVE-2018-1273
Oracle Oracle Financial Services Applications Risk Matrix: Studio (Spring Data Commons) vulnerability
CVE: CVE-2018-1273
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
CISA
VMware Tanzu Spring Data Commons Property Binder Vulnerability
cisa·2022-03-25·CVSS 9.8
CVE-2018-1273 [CRITICAL] CWE-94 VMware Tanzu Spring Data Commons Property Binder Vulnerability
Vulnerability: VMware Tanzu Spring Data Commons Property Binder Vulnerability
Affected: VMware Tanzu Spring Data Commons
Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-1273
Remediation Due Date: 2022-04-15
Red Hat
spring-data-commons: Improper neutralization of special elements allow remote attackers to execute code via crafted requests
vendor_redhat·2018-03-27·CVSS 9.8
CVE-2018-1273 [CRITICAL] CWE-138 spring-data-commons: Improper neutralization of special elements allow remote attackers to execute code via crafted requests
spring-data-commons: Improper neutralization of special elements allow remote attackers to execute code via crafted requests
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
Package: spring-data-commons (Red Hat Fuse 7) - Affected
Package: spring-data-commons (Red Hat JBoss Fuse 6) - Not affected
Package: spring-data-commons (Red Hat JBoss Fuse Integration Service 2) - Not affected
No detection rules found.
Nuclei
Spring Data Commons - Remote Code Execution
nuclei·CVSS 9.8
CVE-2018-1273 [CRITICAL] Spring Data Commons - Remote Code Execution
Spring Data Commons - Remote Code Execution
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5,
and older unsupported versions, contain a property binder vulnerability
caused by improper neutralization of special elements.
An unauthenticated remote malicious user (or attacker) can supply
specially crafted request parameters against Spring Data REST backed HTTP resources
or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
Template:
id: CVE-2018-1273
info:
name: Spring Data Commons - Remote Code Execution
author: dwisiswant0
severity: critical
description: |
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5,
and older unsupported versions, contain a property binder vulnerability
caused by imp
Unit42
WatchDog: Exposing a Cryptojacking Campaign That’s Operated for Two Years
blogs_unit42·2021-02-17
WatchDog: Exposing a Cryptojacking Campaign That’s Operated for Two Years
## Executive Summary
Unit 42 researchers are exposing one of the largest and longest-lasting Monero cryptojacking operations known to exist. The operation is called WatchDog, taken from the name of a Linux daemon called watchdogd. The WatchDog mining operation has been running since Jan. 27, 2019, and has collected at least 209 Monero (XMR), valued to be around $32,056 USD. Researchers have determined that at least 476 compromised systems, composed primarily of Windows and NIX cloud instances, have been performing mining operations at any one time for over two years.
Cryptojacking is the process of performing cryptomining operations on systems which are not owned and maintained by the mining operators. Malicious cryptojacking operations are currently estimated to affect 23% of cloud envi
Unit42
WatchDog: Exposing a Cryptojacking Campaign That’s Operated for Two Years
blogs_unit42·2021-02-17
WatchDog: Exposing a Cryptojacking Campaign That’s Operated for Two Years
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## WatchDog: Exposing a Cryptojacking Campaign That’s Operated for Two Years
Nathaniel Quist
Published: February 17, 2021
Cloud Cybersecurity Research
Malware
Threat Research
Cryptojacking
GoLang
Monero
XMRig
## Executive Summary
Unit 42 researchers are exposing one of the largest and longest-lasting Monero cryptojacking operations known to exist. The operation is called WatchDog, taken from the name of a Linux daemon called watchdogd . The WatchDog mining operation has been running since Jan. 27, 2019, and has collected at least 209 Monero (XMR), valued to be around $32,056 USD. Researchers have determined that at least 476 compromised systems, composed primarily of Windows and NIX cloud instances, have
Fortinet
A Closer Look at Satan Ransomware’s Propagation Techniques
blogs_fortinet·2019-05-20·CVSS 5.3
[MEDIUM] A Closer Look at Satan Ransomware’s Propagation Techniques
FORTIGUARD LABS THREAT RESEARCH
A Closer Look at Satan Ransomware’s Propagation Techniques
By David Maciejak and Floser Bacurio Jr. | May 20, 2019
FortiGuard Labs Breaking Threat Research
Satan ransomware first appeared in early 2017, and since then threat actors have been constantly improving the malware to infect its victims more effectively and to maximize its profits. For instance, FortiGuard Labs has discovered a campaign which was also utilizing a cryptominer malware as an additional payload to maximize its profits from its victims.
Aside from the fact that this file-encrypting malware targets both Linux and Windows platform, it also employs numerous vulnerabilities to propagate itself through public and external networks. In fact, FortiGuard Labs has discovered a new variant t
Talos
Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch Clusters
blogs_talos·2019-02-26·CVSS 8.1
[HIGH] Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch Clusters
## Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch Clusters
Christopher Evans of Cisco Talos conducted the research for this post.
## EXECUTIVE SUMMARY
Cisco Talos warns users that they need to keep a close eye on unsecured Elasticsearch clusters. We have recently observed a spike in attacks from multiple threat actors targeting these clusters. These attackers are targeting clusters using versions 1.4.2 and lower, and are leveraging old vulnerabilities to pass scripts to search queries and drop the attacker's payloads. These scripts are being leveraged to drop both malware and cryptocurrency miners on victim machines. Talos has also been able to identify social media accounts associated with one of these threat actors. Because Elasticsearch is typically used to ma
Talos
Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch Clusters
blogs_talos·2019-02-26·CVSS 8.1
[HIGH] Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch Clusters
Christopher Evans of Cisco Talos conducted the research for this post.
## EXECUTIVE SUMMARY
Cisco Talos warns users that they need to keep a close eye on unsecured Elasticsearch clusters. We have recently observed a spike in attacks from multiple threat actors targeting these clusters. These attackers are targeting clusters using versions 1.4.2 and lower, and are leveraging old vulnerabilities to pass scripts to search queries and drop the attacker's payloads. These scripts are being leveraged to drop both malware and cryptocurrency miners on victim machines. Talos has also been able to identify social media accounts associated with one of these threat actors. Because Elasticsearch is typically used to manage very large datasets, the repercussions of a successful attack on a cluster coul
Greynoiseio
NoiseLetter March 2026
blogs_greynoiseio
NoiseLetter March 2026
Events, events… and yes, even more events. 🌍 GreyNoise has been on the move. March kept us busy with stops at eCrimes in London and SecIT in Hanover—but we’re just getting started. Over the next few months, we’ll be hitting the road for CrowdStrike CrowdTours across eight cities, heading to Glasgow to speak and sponsor CyberUK, and making our way to Tampa for H-ISAC. If you’ll be at any of these (or nearby), we’d love to connect.
And while we’ve been racking up miles, we haven’t slowed down on the research front. We’ve just released some exciting new findings—with even more coming in the next few weeks—so keep an eye out.
Thanks, as always, for being part of the GreyNoise community.
Featured
About this new report
Every enterprise firewall processes traffic from residential IP space. T
Greynoiseio
Battling Ransomware One Tag At A Time
blogs_greynoiseio
Battling Ransomware One Tag At A Time
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Bugzilla
CVE-2018-1273 spring-data-commons: Improper neutralization of special elements allow remote attackers to execute code via crafted requests
bugzilla·2018-04-11·CVSS 9.8
CVE-2018-1273 [CRITICAL] CVE-2018-1273 spring-data-commons: Improper neutralization of special elements allow remote attackers to execute code via crafted requests
CVE-2018-1273 spring-data-commons: Improper neutralization of special elements allow remote attackers to execute code via crafted requests
Spring Data Commons, versions 1.13 to 1.13.10 and 2.0 to 2.0.5, , contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data’s projection-based request payload binding hat can lead to a remote code execution attack.
External References:
https://pivotal.io/security/cve-2018-1273
Upstream Issue:
https://jira.spring.io/browse/DATACMNS-1282
Upstream Patches:
https://github.com/spring-projects/spring-data-commons/commit/b1a20ae1e82a63f99b3afc6f2
arXiv
Partially-Observable Security Games for Automating Attack-Defense Analysis
arxiv_fulltext·2022-11-02
Partially-Observable Security Games for Automating Attack-Defense Analysis
Partially-Observable Security Games for Automating Attack-Defense Analysis
Narges Khakpour
[email protected]
School of Computing, Newcastle University
Newcastle upon Tyne
UK
Department of Computer Science and Media Technology, Linnaeus University
Växjö
Sweden
David Parker
[email protected]
Department of Computer Science, Oxford University
Oxford
UK
## Abstract
Network systems often contain vulnerabilities that remain unfixed in a network for various reasons, such as the lack of a patch or knowledge to fix them. With the presence of such residual vulnerabilities, the network administrator should properly react to the malicious activities or proactively prevent them, by applying suitable countermeasures that minimize the likelihood of an attack by the attacker. In this
http://mail-archives.apache.org/mod_mbox/ignite-dev/201807.mbox/%3CCAK0qHnqzfzmCDFFi6c5Jok19zNkVCz5Xb4sU%3D0f2J_1i4p46zQ%40mail.gmail.com%3Ehttps://pivotal.io/security/cve-2018-1273https://www.oracle.com/security-alerts/cpujul2022.htmlhttp://mail-archives.apache.org/mod_mbox/ignite-dev/201807.mbox/%3CCAK0qHnqzfzmCDFFi6c5Jok19zNkVCz5Xb4sU%3D0f2J_1i4p46zQ%40mail.gmail.com%3Ehttps://pivotal.io/security/cve-2018-1273https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-1273
2018-04-11
Published
2022-03-25
Added to CISA KEV
Exploited in the wild