oracle application-testing-suite CVE-2018-1272 vulnerability in Oracle and Other Products
Published on April 6, 2018

product logo product logo product logo
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

Vendor Advisory Vendor Advisory NVD


Products Associated with CVE-2018-1272

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2018-1272 are published in these products:

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Affected Versions

Spring by Pivotal Spring Framework Version Versions prior to 5.0.5 and 4.3.15 is affected by CVE-2018-1272

Exploit Probability

EPSS
1.68%
Percentile
81.89%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.