SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-1272

When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted…

HIGH 7.5EPSS 3.08%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
3.08% probability · 87th percentile
CISA KEV
Not listed
Affected
vmware/spring framework · oracle/application testing suite · oracle/big data discovery · oracle/communications converged application server · oracle/communications diameter signaling router · oracle/communications performance intelligence center · oracle/communications services gatekeeper · oracle/enterprise manager ops center · oracle/goldengate for big data · oracle/health sciences information manager · oracle/healthcare master person index · oracle/insurance calculation engine · oracle/insurance rules palette · oracle/primavera gateway · oracle/retail back office · oracle/retail central office · oracle/retail customer insights · oracle/retail integration bus · oracle/retail open commerce platform · oracle/retail order broker · +5 more
Source
security_alert@emc.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.