imPC@ndo IT

Tracker / CVE-2018-1257

CVE-2018-1257

Medium 6.5

Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.

Affected products and versions

oracle agile_product_lifecycle_management
oracle application_testing_suite
oracle big_data_discovery
oracle communications_converged_application_server · … → 7.0.0.1
oracle communications_diameter_signaling_router · … → 8.3
oracle communications_performance_intelligence_center · … → 10.2.1
oracle communications_services_gatekeeper · … → 6.1.0.4.0
oracle communications_unified_inventory_management
oracle endeca_information_discovery_integrator
oracle enterprise_manager_base_platform
oracle enterprise_manager_for_mysql_database
oracle enterprise_manager_ops_center
oracle flexcube_private_banking
oracle goldengate_for_big_data
oracle health_sciences_information_manager
oracle healthcare_master_person_index
oracle hospitality_guest_access
oracle insurance_calculation_engine
oracle insurance_rules_palette
oracle primavera_gateway
oracle retail_customer_insights
oracle retail_open_commerce_platform
oracle retail_order_broker
oracle retail_predictive_application_server
oracle service_architecture_leveraging_tuxedo
oracle tape_library_acsls
oracle utilities_network_management_system
oracle weblogic_server
redhat openshift
vmware spring_framework · … → 4.3.17
vmware spring_framework · 5.0.0 → 5.0.6

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References