Vulnerability CVE-2018-1272


Published: 2018-04-06

Description:
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

Vendor: Oracle
Product: Tape library acsls 
Version: 8.4;
Product: Communications diameter signaling router 
Version:
8.2
8.1
6.0
Product: Retail open commerce platform 
Version:
6.0.1
6.0.0
5.3.0
Product: Retail order broker 
Version:
5.2
5.1
16.0
15.0
Product: Healthcare master person index 
Version: 4.0; 3.0;
Product: Health sciences information manager 
Version: 3.0;
Product: Primavera gateway 
Version:
17.12
16.2
15.2
Product: Retail integration bus 
Version:
16.0.2
16.0.1
16.0
15.0.2
15.0.1
15.0.0.1
14.1.3
14.1.2
14.1.1
14.0.4
14.0.3
14.0.2
14.0.1
Product: Retail customer insights 
Version: 16.0; 15.0;
Product: Retail predictive application server 
Version:
16.0
15.0
14.1
14.0
Product: Retail returns management 
Version: 14.1; 14.0;
Product: Retail back office 
Version: 14.1; 14.0;
Product: Retail central office 
Version: 14.1; 14.0;
Product: Retail point-of-sale 
Version: 14.1; 14.0;
Product: Application testing suite 
Version:
13.3.0.1
13.2.0.1
13.1.0.1
12.5.0.3
Product: Enterprise manager ops center 
Version: 12.3.3; 12.2.2;
Product: Goldengate for big data 
Version:
12.3.2.1
12.3.1.1
12.2.0.1
Product: Service architecture leveraging tuxedo 
Version: 12.2.2.0.0; 12.1.3.0.0;
Product: Insurance rules palette 
Version:
11.1
11.0
10.2
10.1
10.0
Product: Insurance calculation engine 
Version:
10.2.1
10.2
10.1.1
Product: Big data discovery 
Version: 1.6.0;
Vendor: Pivotal software
Product: Spring framework 
Version:
5.0.4
5.0.3
5.0.2
5.0.1
5.0.0
4.3.9
4.3.8
4.3.7
4.3.6
4.3.5
4.3.4
4.3.3
4.3.2
4.3.14
4.3.13
4.3.12
4.3.11
4.3.10
4.3.1
4.3.0
4.2.9

CVSS2 => (AV:N/AC:M/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6/10
6.4/10
6.8/10
Exploit range
Attack complexity
Authentication
Remote
Medium
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial

 References:
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
http://www.securityfocus.com/bid/103697
https://access.redhat.com/errata/RHSA-2018:1320
https://access.redhat.com/errata/RHSA-2018:2669
https://exchange.xforce.ibmcloud.com/vulnerabilities/141286
https://pivotal.io/security/cve-2018-1272
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html

Related CVE
CVE-2019-11276
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x prior to 2.6.3, makes a request to the /cloudapplication endpoint via Spring actuator, and subsequent...
CVE-2019-11270
Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrar...
CVE-2019-11273
Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable component which logs the username and password to the billing database. A remote authenticated user with access to those logs may...
CVE-2019-3794
Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking attacks on UAA's frontend sites.
CVE-2019-11268
Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all other identity zones and obtain ...
CVE-2019-11272
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user...
CVE-2019-3787
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending ?unknown.org? to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which leads to attack v...
CVE-2019-11269
Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicio...

Copyright 2019, cxsecurity.com

 

Back to Top