Tracker / CVE-2018-11039
CVE-2018-11039
Medium 5.9
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.
Affected products and versions
| debian | debian_linux |
|---|---|
| oracle | agile_plm |
| oracle | application_testing_suite |
| oracle | communications_diameter_signaling_router · … → 8.3 |
| oracle | communications_network_integrity · 7.3.2 → 7.3.6 |
| oracle | communications_online_mediation_controller |
| oracle | communications_performance_intelligence_center · … → 10.2.1 |
| oracle | communications_services_gatekeeper · … → 6.1.0.4.0 |
| oracle | communications_unified_inventory_management |
| oracle | endeca_information_discovery_integrator |
| oracle | enterprise_manager_base_platform |
| oracle | enterprise_manager_for_mysql_database |
| oracle | enterprise_manager_ops_center |
| oracle | health_sciences_information_manager |
| oracle | healthcare_master_person_index |
| oracle | hospitality_guest_access |
| oracle | insurance_calculation_engine |
| oracle | insurance_calculation_engine · 11.0.0 → 11.3.1 |
| oracle | insurance_rules_palette |
| oracle | micros_lucas |
| oracle | mysql_enterprise_monitor · … → 3.4.9.4237 |
| oracle | mysql_enterprise_monitor · 4.0.0 → 4.0.6.5281 |
| oracle | mysql_enterprise_monitor · 8.0.0 → 8.0.2.8191 |
| oracle | primavera_p6_enterprise_project_portfolio_management |
| oracle | retail_advanced_inventory_planning |
| oracle | retail_assortment_planning |
| oracle | retail_clearance_optimization_engine |
| oracle | retail_customer_insights |
| oracle | retail_financial_integration |
| oracle | retail_integration_bus |
| oracle | retail_markdown_optimization |
| oracle | retail_predictive_application_server |
| oracle | retail_xstore_point_of_service |
| oracle | utilities_network_management_system |
| oracle | weblogic_server |
| vmware | spring_framework · … → 4.3.18 |
| vmware | spring_framework · 5.0.0 → 5.0.7 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.