4
CVSSv2

CVE-2018-1257

Published: 11/05/2018 Updated: 24/08/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

Spring Framework, versions 5.0.x before 5.0.6, versions 4.3.x before 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pivotal software spring framework

redhat openshift -

oracle enterprise manager ops center 12.3.3

oracle enterprise manager base platform 12.1.0.5.0

oracle enterprise manager base platform 13.2.0.0.0

oracle enterprise manager base platform 13.3.0.0.0

oracle communications converged application server

oracle communications diameter signaling router

oracle communications performance intelligence center

oracle communications services gatekeeper

oracle insurance calculation engine 10.2.1

oracle insurance rules palette 10.0

oracle insurance rules palette 10.1

oracle insurance rules palette 10.2

oracle weblogic server 12.1.3.0.0

oracle application testing suite 12.5.0.3

oracle weblogic server 10.3.6.0.0

oracle weblogic server 12.2.1.3.0

oracle health sciences information manager 3.0

oracle healthcare master person index 3.0

oracle retail customer insights 15.0

oracle retail customer insights 16.0

oracle retail predictive application server 14.0

oracle retail predictive application server 14.1

oracle retail order broker 15.0

oracle retail order broker 16.0

oracle retail open commerce platform 5.3.0

oracle primavera gateway 17.12

oracle goldengate for big data 12.3.1.1

oracle goldengate for big data 12.3.2.1

oracle agile product lifecycle management 9.3.3

oracle agile product lifecycle management 9.3.4

oracle agile product lifecycle management 9.3.5

oracle agile product lifecycle management 9.3.6

oracle utilities network management system 1.12.0.3

oracle flexcube private banking 2.0.0.0

oracle flexcube private banking 12.0.1.0

oracle flexcube private banking 12.1.0.0

oracle flexcube private banking 2.2.0.1

oracle primavera gateway 16.2

oracle primavera gateway 15.2

oracle hospitality guest access 4.2.0

oracle hospitality guest access 4.2.1

oracle endeca information discovery integrator 3.2.0

oracle endeca information discovery integrator 3.1.0

oracle retail open commerce platform 6.0.1

oracle application testing suite 13.1.0.1

oracle application testing suite 13.2.0.1

oracle application testing suite 13.3.0.1

oracle healthcare master person index 4.0

oracle insurance calculation engine 10.2

oracle tape library acsls 8.4

oracle service architecture leveraging tuxedo 12.1.3.0.0

oracle service architecture leveraging tuxedo 12.2.2.0.0

oracle retail predictive application server 15.0

oracle retail predictive application server 16.0

oracle retail order broker 5.1

oracle retail order broker 5.2

oracle retail open commerce platform 6.0.0

oracle insurance calculation engine 10.1.1

oracle insurance rules palette 11.0

oracle insurance rules palette 11.1

oracle big data discovery 1.6.0

oracle goldengate for big data 12.2.0.1

oracle enterprise manager for mysql database 13.2

oracle flexcube private banking 12.0.3.0

oracle communications unified inventory management 7.3.2

oracle communications unified inventory management 7.3.4

oracle communications unified inventory management 7.3.5

oracle communications unified inventory management 7.4.0

Vendor Advisories

Synopsis Important: Red Hat OpenShift Application Runtimes Spring Boot security and bug fix update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift Application RuntimesRed Hat Product Security has rated this update as having a security impact of Important A ...
Spring Framework, versions 50x prior to 506, versions 43x prior to 4317, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression ...
Synopsis Important: Red Hat Fuse 72 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat FuseRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a de ...
Oracle Critical Patch Update Advisory - January 2019 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities Critical Patch Update patches are usually cumulative, but each advisory describes only the security fixes added since the previou ...
Oracle Critical Patch Update Advisory - October 2018 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities Critical Patch Update patches are usually cumulative, but each advisory describes only the security fixes added since the previou ...
There are multiple vulnerabilities identified in IBM Guardium Data Encryption (GDE) These vulnerabilities have been fixed in GDE 4004 Please apply the latest version for the fixes ...

Github Repositories

Cyber Securiy MOOC Unsecure project

LINK: githubcom/ilmari666/cybsec Based on the Springboot-template as per course material that can be installed and run with suitably configured Netbeans and Maven Five flaws as per wwwowasporg/images/7/72/OWASP_Top_10-2017_%28en%29pdfpdf This document can be read at githubcom/ilmari666/cybsec/blob/master/READMEmd FLAW 1: A2:2017 Broken Authentica