Spring Framework (versions 5.0.x before 5.0.7, versions 4.3.x before 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
vmware spring framework |
||
oracle retail xstore point of service 7.1 |
||
oracle weblogic server 12.1.3.0.0 |
||
oracle application testing suite 12.5.0.3 |
||
oracle hospitality guest access 4.2.0 |
||
oracle hospitality guest access 4.2.1 |
||
oracle weblogic server 10.3.6.0.0 |
||
oracle weblogic server 12.2.1.3.0 |
||
oracle enterprise manager ops center 12.3.3 |
||
oracle primavera p6 enterprise project portfolio management 18.8 |
||
oracle endeca information discovery integrator 3.2.0 |
||
oracle endeca information discovery integrator 3.1.0 |
||
oracle application testing suite 13.1.0.1 |
||
oracle application testing suite 13.2.0.1 |
||
oracle application testing suite 13.3.0.1 |
||
oracle communications diameter signaling router |
||
oracle communications performance intelligence center |
||
oracle insurance rules palette 10.0 |
||
oracle insurance rules palette 10.2 |
||
oracle communications services gatekeeper |
||
oracle health sciences information manager 3.0 |
||
oracle healthcare master person index 3.0 |
||
oracle healthcare master person index 4.0 |
||
oracle insurance calculation engine 10.2 |
||
oracle retail customer insights 15.0 |
||
oracle retail customer insights 16.0 |
||
oracle retail predictive application server 16.0 |
||
oracle enterprise manager for mysql database 13.2 |
||
oracle retail integration bus 14.1.2 |
||
oracle retail assortment planning 15.0 |
||
oracle utilities network management system 1.12.0.3 |
||
oracle communications online mediation controller 6.1 |
||
oracle retail clearance optimization engine 14.0.5 |
||
oracle agile plm 9.3.3 |
||
oracle agile plm 9.3.4 |
||
oracle agile plm 9.3.5 |
||
oracle agile plm 9.3.6 |
||
oracle retail assortment planning 14.1 |
||
oracle retail assortment planning 16.0 |
||
oracle retail financial integration 13.2 |
||
oracle retail financial integration 14.0 |
||
oracle retail financial integration 14.1 |
||
oracle retail financial integration 15.0 |
||
oracle retail financial integration 16.0 |
||
oracle micros lucas 2.9.5 |
||
oracle enterprise manager base platform 13.2.0.0.0 |
||
oracle enterprise manager base platform 12.1.0.5.0 |
||
oracle enterprise manager base platform 13.3.0.0.0 |
||
oracle communications unified inventory management 7.3.2 |
||
oracle communications unified inventory management 7.3.4 |
||
oracle communications unified inventory management 7.3.5 |
||
oracle communications unified inventory management 7.4.0 |
||
oracle mysql enterprise monitor |
||
oracle communications network integrity |
||
oracle retail advanced inventory planning 15.0 |
||
oracle insurance calculation engine |
||
oracle retail markdown optimization 13.4.4 |
||
oracle retail predictive application server 15.0.3..100 |
||
oracle retail predictive application server 14.1.3.37 |
||
oracle retail predictive application server 14.0.3.26 |
||
debian debian linux 9.0 |