Pivotal Spring Framework CVE-2018-1275 Incomplete Fix Remote Code Execution Vulnerability

Bugtraq ID: 103771
Class: Input Validation Error
CVE: CVE-2018-1275
Remote: Yes
Local: No
Published: Apr 13 2018 12:00AM
Updated: Jul 17 2019 07:00AM
Credit: rwx, Christoph Dreis, and 0c0c0f.
Vulnerable: Pivotal Spring Framework 5.0.4
Pivotal Spring Framework 5.0.3
Pivotal Spring Framework 5.0.2
Pivotal Spring Framework 5.0.1
Pivotal Spring Framework 5.0
Pivotal Spring Framework 4.3.15
Pivotal Spring Framework 4.3.14
Pivotal Spring Framework 4.3
Oracle Tape Library ACSLS 8.4
Oracle SOA Suite 12.2.1.3.0
Oracle SOA Suite 12.1.3.0.0
Oracle Retail Predictive Application Server 16.0
Oracle Retail Predictive Application Server 15.0
Oracle Retail Predictive Application Server 14.1
Oracle Retail Predictive Application Server 14.0
Oracle Retail Order Broker 5.2
Oracle Retail Order Broker 5.1
Oracle Retail Order Broker 16.0
Oracle Retail Order Broker 15.0
Oracle Retail Open Commerce Platform 6.0.1
Oracle Retail Open Commerce Platform 6.0
Oracle Retail Open Commerce Platform 5.3
Oracle Primavera Gateway 17.12
Oracle Primavera Gateway 16.2
Oracle Primavera Gateway 15.2
Oracle Insurance Rules Palette 11.1
Oracle Insurance Rules Palette 11.0
Oracle Insurance Rules Palette 10.2.0
Oracle Insurance Rules Palette 10.1
Oracle Insurance Rules Palette 10.0
Oracle Insurance Calculation Engine 10.2.1
Oracle Insurance Calculation Engine 10.1.1
Oracle GoldenGate for Big Data 12.3.2.1
Oracle GoldenGate for Big Data 12.3.1.1
Oracle GoldenGate for Big Data 12.2.0.1
Oracle GoldenGate Application Adapters 12.3.2.1.1
Oracle FLEXCUBE Investor Servicing 14.0
Oracle FLEXCUBE Investor Servicing 12.4
Oracle FLEXCUBE Investor Servicing 12.3
Oracle FLEXCUBE Investor Servicing 12.1
Oracle FLEXCUBE Investor Servicing 12.0.4
Oracle Communications WebRTC Session Controller 7.1
Oracle Communications WebRTC Session Controller 7.0
Oracle Communications WebRTC Session Controller 0
Oracle Communications Service Broker 6.0
Oracle Communications Online Mediation Controller 6.1
Oracle Communications Converged Application Server Service Controller 6.1
Oracle Communications Converged Application Server - Service Controller 6.1
Oracle Communications Converged Application Server - Service Controller 6.0
Oracle Big Data Discovery 1.6
Not Vulnerable: Pivotal Spring Framework 5.0.5
Pivotal Spring Framework 4.3.16
Oracle Communications WebRTC Session Controller 7.2


 

Privacy Statement
Copyright 2010, SecurityFocus