9.8

CVE-2017-8046

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Boot Version < 1.5.9
VMware ≫ Spring Boot Version 2.0.0 Update milestone1
VMware ≫ Spring Boot Version 2.0.0 Update milestone2
VMware ≫ Spring Boot Version 2.0.0 Update milestone3
VMware ≫ Spring Boot Version 2.0.0 Update milestone4
VMware ≫ Spring Boot Version 2.0.0 Update milestone5
Pivotal Software ≫ Spring Data Rest Version 3.0.0 Update m1
Pivotal Software ≫ Spring Data Rest Version 3.0.0 Update m2
Pivotal Software ≫ Spring Data Rest Version 3.0.0 Update m3
Pivotal Software ≫ Spring Data Rest Version 3.0.0 Update m4
VMware ≫ Spring Data Rest Version < 2.6.9
VMware ≫ Spring Data Rest Version 3.0.0 Update rc1
VMware ≫ Spring Data Rest Version 3.0.0 Update rc2
VMware ≫ Spring Data Rest Version 3.0.0 Update rc3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 74.53% 0.995
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.securityfocus.com/bid/100948
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHSA-2018:2405
https://pivotal.io/security/cve-2017-8046
Vendor Advisory
https://www.exploit-db.com/exploits/44289/
Third Party Advisory
VDB Entry