SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-11039

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC.

MEDIUM 5.9EPSS 2.75%

Does this matter?

Lower severity and a low EPSS score (2.75%). Track it; it rarely justifies an emergency change on its own.

Description

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
2.75% probability · 85th percentile
CISA KEV
Not listed
Affected
vmware/spring framework · oracle/agile product lifecycle management · oracle/application testing suite · oracle/communications diameter signaling router · oracle/communications network integrity · oracle/communications online mediation controller · oracle/communications performance intelligence center · oracle/communications services gatekeeper · oracle/communications unified inventory management · oracle/endeca information discovery integrator · oracle/enterprise manager base platform · oracle/enterprise manager for mysql database · oracle/enterprise manager ops center · oracle/health sciences information manager · oracle/healthcare master person index · oracle/hospitality guest access · oracle/insurance calculation engine · oracle/insurance rules palette · oracle/micros lucas · oracle/mysql enterprise monitor · +13 more
Source
security_alert@emc.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.