CVE-2018-1273Patch(apache / financial_services_crime_and_compliance_management_studio)
LOWCVSS 9.8 · CRITICALCISA KEVSignal is active with 1 mentions in latest observed window
Immediate actions
- Patch apache financial_services_crime_and_compliance_management_studio systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
Sources & remediation
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-04-15. Apply updates per vendor instructions.
- http://mail-archives.apache.org/mod_mbox/ignite-dev/201807.mbox/%3CCAK0qHnqzfzmCDFFi6c5Jok19zNkVCz5Xb4sU%3D0f2J_1i4p46zQ%40mail.gmail.com%3E
- https://pivotal.io/security/cve-2018-1273
- http://mail-archives.apache.org/mod_mbox/ignite-dev/201807.mbox/%3CCAK0qHnqzfzmCDFFi6c5Jok19zNkVCz5Xb4sU%3D0f2J_1i4p46zQ%40mail.gmail.com%3E
- https://pivotal.io/security/cve-2018-1273
Priority
LOW
Exploitation
ACTIVE
PoC
NONE
Patch
AVAILABLE
Momentum
NONE
Are you affected?
If you run products in this scope, you should treat this CVE as relevant to your environment.
- financial_services_crime_and_compliance_management_studio
- ignite
- spring_data_commons
- spring_data_rest
Threat summary
- Patch or workaround signal is available
- 1 mentions across 1 observed day
What's happening
- Patch or workaround mentioned in 1 signal
- Technical details provided in 1 signal
- 1 total mentions across 1 day
Affected systems
3 versions affected across 4 products
Deep dive
Activity timeline1 mentions / 1d
Signal classification1 categories
CPE platform detail8 entries
8 of 8 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | apache | ignite | - | - | - |
| App | apache | ignite | 1.0.0 | - | - |
| App | apache | ignite | 1.0.0 | - | - |
| App | broadcom | spring_data_commons | - | - | - |
| App | oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.2.0 | - | - |
| App | oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.3.0 | - | - |
| App | pivotal_software | spring_data_rest | - | - | - |
| App | vmware | spring_data_rest | - | - | - |
