imPC@ndo EN

Tracker / CVE-2018-1272

CVE-2018-1272

Alta 7.5

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

Prodotti e versioni affette

oracle application_testing_suite
oracle big_data_discovery
oracle communications_converged_application_server · … → 7.0.0.1
oracle communications_diameter_signaling_router · … → 8.3
oracle communications_performance_intelligence_center · … → 10.2.1
oracle communications_services_gatekeeper · … → 6.1.0.4.0
oracle enterprise_manager_ops_center
oracle goldengate_for_big_data
oracle health_sciences_information_manager
oracle healthcare_master_person_index
oracle insurance_calculation_engine
oracle insurance_rules_palette
oracle primavera_gateway
oracle retail_back_office
oracle retail_central_office
oracle retail_customer_insights
oracle retail_integration_bus
oracle retail_open_commerce_platform
oracle retail_order_broker
oracle retail_point-of-sale
oracle retail_predictive_application_server
oracle retail_returns_management
oracle service_architecture_leveraging_tuxedo
oracle tape_library_acsls
vmware spring_framework · 4.3.0 → 4.3.15
vmware spring_framework · 5.0 → 5.0.5

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti