imPC@ndo IT

Tracker / CVE-2018-1271

CVE-2018-1271

Medium 5.9

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.

Affected products and versions

oracle application_testing_suite
oracle big_data_discovery
oracle communications_converged_application_server · … → 7.0.0.1
oracle communications_diameter_signaling_router · … → 8.3
oracle communications_performance_intelligence_center · … → 10.2.1
oracle communications_policy_management
oracle communications_services_gatekeeper · … → 6.1.0.4.0
oracle enterprise_manager_ops_center
oracle goldengate_for_big_data
oracle health_sciences_information_manager
oracle healthcare_master_person_index
oracle insurance_calculation_engine
oracle insurance_calculation_engine · 11.0.0 → 11.3.1
oracle insurance_rules_palette
oracle primavera_gateway
oracle rapid_planning
oracle retail_back_office
oracle retail_central_office
oracle retail_customer_insights
oracle retail_integration_bus
oracle retail_open_commerce_platform
oracle retail_order_broker
oracle retail_point-of-sale
oracle retail_predictive_application_server
oracle retail_returns_management
oracle retail_xstore_point_of_service
oracle service_architecture_leveraging_tuxedo
oracle tape_library_acsls
vmware spring_framework · 4.3.0 → 4.3.15
vmware spring_framework · 5.0.0 → 5.0.5

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References