Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-15756


Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack. This vulnerability affects applications that depend on either spring-webmvc or spring-webflux. Such applications must also have a registration for serving static resources (e.g. JS, CSS, images, and others), or have an annotated controller that returns an org.springframework.core.io.Resource. Spring Boot applications that depend on spring-boot-starter-web or spring-boot-starter-webflux are ready to serve static resources out of the box and are therefore vulnerable.


Published

2018-10-18T22:29:00.443

Last Modified

2024-11-21T03:51:24.640

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application vmware spring_framework < 4.3.20 Yes
Application vmware spring_framework < 5.0.10 Yes
Application vmware spring_framework 5.1.0 Yes
Application oracle agile_plm 9.3.3 Yes
Application oracle agile_plm 9.3.4 Yes
Application oracle agile_plm 9.3.5 Yes
Application oracle agile_plm 9.3.6 Yes
Application oracle communications_brm_-_elastic_charging_engine 11.3 Yes
Application oracle communications_brm_-_elastic_charging_engine 12.0 Yes
Application oracle communications_converged_application_server_-_service_controller 6.0 Yes
Application oracle communications_converged_application_server_-_service_controller 6.1 Yes
Application oracle communications_diameter_signaling_router 8.0.0 Yes
Application oracle communications_diameter_signaling_router 8.1 Yes
Application oracle communications_diameter_signaling_router 8.2 Yes
Application oracle communications_diameter_signaling_router 8.2.1 Yes
Application oracle communications_element_manager 8.1.1 Yes
Application oracle communications_element_manager 8.2.0 Yes
Application oracle communications_element_manager 8.2.1 Yes
Application oracle communications_online_mediation_controller 6.1 Yes
Application oracle communications_session_report_manager 8.0.0 Yes
Application oracle communications_session_report_manager 8.1.0 Yes
Application oracle communications_session_report_manager 8.1.1 Yes
Application oracle communications_session_report_manager 8.2.0 Yes
Application oracle communications_session_report_manager 8.2.1 Yes
Application oracle communications_session_route_manager 8.0.0 Yes
Application oracle communications_session_route_manager 8.1.0 Yes
Application oracle communications_session_route_manager 8.1.1 Yes
Application oracle communications_session_route_manager 8.2.0 Yes
Application oracle communications_session_route_manager 8.2.1 Yes
Application oracle communications_unified_inventory_management 7.3 Yes
Application oracle communications_unified_inventory_management 7.4.0 Yes
Application oracle endeca_information_discovery_integrator 3.2.0 Yes
Application oracle enterprise_manager_for_fusion_applications 13.3.0.0 Yes
Application oracle enterprise_manager_ops_center 12.3.3 Yes
Application oracle financial_services_analytical_applications_infrastructure ≤ 8.0.8 Yes
Application oracle flexcube_private_banking 12.0.1 Yes
Application oracle flexcube_private_banking 12.0.3 Yes
Application oracle flexcube_private_banking 12.1.0 Yes
Application oracle goldengate_application_adapters 12.3.2.1.0 Yes
Application oracle healthcare_master_person_index 3.0 Yes
Application oracle healthcare_master_person_index 4.0.2 Yes
Application oracle identity_manager_connector 9.0 Yes
Application oracle insurance_calculation_engine 9.7 Yes
Application oracle insurance_calculation_engine 10.0 Yes
Application oracle insurance_calculation_engine 10.1 Yes
Application oracle insurance_calculation_engine 10.2 Yes
Application oracle insurance_policy_administration_j2ee 10.0 Yes
Application oracle insurance_policy_administration_j2ee 10.1 Yes
Application oracle insurance_policy_administration_j2ee 10.2 Yes
Application oracle insurance_policy_administration_j2ee 10.2.0 Yes
Application oracle insurance_policy_administration_j2ee 10.2.4 Yes
Application oracle insurance_policy_administration_j2ee 11.0 Yes
Application oracle insurance_policy_administration_j2ee 11.1.0 Yes
Application oracle insurance_policy_administration_j2ee 11.2.0 Yes
Application oracle insurance_rules_palette 10.0 Yes
Application oracle insurance_rules_palette 10.1 Yes
Application oracle insurance_rules_palette 10.2 Yes
Application oracle insurance_rules_palette 10.2.0 Yes
Application oracle insurance_rules_palette 10.2.4 Yes
Application oracle insurance_rules_palette 11.0 Yes
Application oracle insurance_rules_palette 11.0.2 Yes
Application oracle insurance_rules_palette 11.1.0 Yes
Application oracle insurance_rules_palette 11.2.0 Yes
Application oracle mysql_enterprise_monitor ≤ 4.0.12 Yes
Application oracle mysql_enterprise_monitor ≤ 8.0.20 Yes
Application oracle primavera_analytics 18.8 Yes
Application oracle primavera_gateway 15.2 Yes
Application oracle primavera_gateway 16.2 Yes
Application oracle primavera_gateway 17.12 Yes
Application oracle primavera_gateway 18.8.0 Yes
Application oracle rapid_planning 12.1 Yes
Application oracle rapid_planning 12.2 Yes
Application oracle retail_advanced_inventory_planning 15.0 Yes
Application oracle retail_assortment_planning 15.0 Yes
Application oracle retail_assortment_planning 16.0 Yes
Application oracle retail_clearance_optimization_engine 14.0.5 Yes
Application oracle retail_financial_integration 14.0 Yes
Application oracle retail_financial_integration 14.1 Yes
Application oracle retail_financial_integration 15.0 Yes
Application oracle retail_financial_integration 16.0 Yes
Application oracle retail_integration_bus 15.0 Yes
Application oracle retail_integration_bus 15.0.3 Yes
Application oracle retail_integration_bus 16.0 Yes
Application oracle retail_integration_bus 16.0.3 Yes
Application oracle retail_invoice_matching 12.0 Yes
Application oracle retail_invoice_matching 13.0 Yes
Application oracle retail_invoice_matching 13.1 Yes
Application oracle retail_invoice_matching 13.2 Yes
Application oracle retail_invoice_matching 14.0 Yes
Application oracle retail_invoice_matching 14.1 Yes
Application oracle retail_markdown_optimization 13.4.4 Yes
Application oracle retail_order_broker 5.1 Yes
Application oracle retail_order_broker 5.2 Yes
Application oracle retail_order_broker 15.0 Yes
Application oracle retail_order_broker 16.0 Yes
Application oracle retail_predictive_application_server 14.0.3 Yes
Application oracle retail_predictive_application_server 14.0.3.26 Yes
Application oracle retail_predictive_application_server 14.1.3 Yes
Application oracle retail_predictive_application_server 14.1.3.37 Yes
Application oracle retail_predictive_application_server 15.0.3 Yes
Application oracle retail_predictive_application_server 15.0.3.100 Yes
Application oracle retail_predictive_application_server 16.0 Yes
Application oracle retail_predictive_application_server 16.0.3 Yes
Application oracle retail_service_backbone 15.0 Yes
Application oracle retail_service_backbone 16.0 Yes
Application oracle retail_service_backbone 16.0.1 Yes
Application oracle retail_xstore_point_of_service 7.1 Yes
Application oracle tape_library_acsls 8.5 Yes
Application oracle webcenter_sites 12.2.1.3.0 Yes
Application oracle weblogic_server 10.3.6.0.0 Yes
Application oracle weblogic_server 12.1.3.0.0 Yes
Application oracle weblogic_server 12.2.1.3.0 Yes
Application oracle weblogic_server 12.2.1.4.0 Yes
Operating System debian debian_linux 9.0 Yes

References