imPC@ndo EN

Tracker / CVE-2018-11040

CVE-2018-11040

Alta 7.5

Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests.

Prodotti e versioni affette

debian debian_linux
oracle agile_product_lifecycle_management
oracle application_testing_suite
oracle communications_network_integrity · 7.3.2 → 7.3.6
oracle communications_online_mediation_controller
oracle communications_services_gatekeeper · … → 6.1.0.4.0
oracle communications_unified_inventory_management
oracle endeca_information_discovery_integrator
oracle enterprise_manager
oracle enterprise_manager_ops_center
oracle flexcube_private_banking
oracle healthcare_master_person_index
oracle hospitality_guest_access
oracle insurance_calculation_engine · 11.0.0 → 11.3.1
oracle insurance_rules_palette
oracle micros_lucas
oracle mysql_enterprise_monitor · … → 3.4.9.4237
oracle mysql_enterprise_monitor · 3.4.10 → 4.0.6.5281
oracle mysql_enterprise_monitor · 4.0.7 → 8.0.2.8191
oracle product_lifecycle_management
oracle retail_advanced_inventory_planning
oracle retail_clearance_optimization_engine
oracle retail_customer_insights
oracle retail_markdown_optimization
oracle retail_predictive_application_server
oracle retail_service_backbone
oracle retail_xstore_point_of_service
oracle utilities_network_management_system
oracle weblogic_server
vmware spring_framework · … → 4.3.18
vmware spring_framework · 5.0.0 → 5.0.7

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti