Vulnerability CVE-2018-11040


Published: 2018-06-25

Description:
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests.

Type:

CWE-254

(Security Features)

Vendor: Oracle
Product: Product lifecycle management 
Version: 9.3.6;
Product: Agile product lifecycle management 
Version:
9.3.5
9.3.4
9.3.3
Product: Communications unified inventory management 
Version:
7.4.0
7.3.5
7.3.4
7.3.2
Product: Hospitality guest access 
Version: 4.2.1; 4.2.0;
Product: Healthcare master person index 
Version: 4.0; 3.0;
Product: Mysql enterprise monitor 
Version: 3.4.9.4237;
Product: Endeca information discovery integrator 
Version: 3.2.0; 3.1.0;
Product: Micros lucas 
Version: 2.9.5;
Product: Flexcube private banking 
Version:
2.2.0.1
2.0.0.0
12.1.0.0
12.0.3.0
12.0.1.0
Product: Retail customer insights 
Version: 16.0; 15.0;
Product: Application testing suite 
Version:
13.3.0.1
13.2.0.1
13.1.0.1
12.5.0.3
Product: Enterprise manager 
Version: 13.2;
Product: Enterprise manager ops center 
Version: 12.3.3;
Product: Weblogic server 
Version: 12.2.1.3.0;
Product: Insurance rules palette 
Version: 10.2; 10.0;
Product: Utilities network management system 
Version: 1.12.0.3;
Vendor: Pivotal software
Product: Spring framework 
Version:
5.0.6
5.0.5
5.0.4
5.0.3
5.0.2
5.0.1
5.0.0
4.3.9
4.3.8
4.3.7
4.3.6
4.3.5
4.3.4
4.3.3
4.3.2
4.3.17
4.3.16
4.3.15
4.3.14
4.3.13
4.3.12
4.3.11
4.3.10
4.3.1
4.3.0

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None

 References:
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
https://pivotal.io/security/cve-2018-11040
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html

Related CVE
CVE-2019-11276
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x prior to 2.6.3, makes a request to the /cloudapplication endpoint via Spring actuator, and subsequent...
CVE-2019-11270
Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrar...
CVE-2019-11273
Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable component which logs the username and password to the billing database. A remote authenticated user with access to those logs may...
CVE-2019-3794
Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking attacks on UAA's frontend sites.
CVE-2019-11268
Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all other identity zones and obtain ...
CVE-2019-11272
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user...
CVE-2019-3787
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending ?unknown.org? to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which leads to attack v...
CVE-2019-11269
Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicio...

Copyright 2019, cxsecurity.com

 

Back to Top