9.8
CVE-2017-8046
- EPSS 74.53%
- Veröffentlicht 04.01.2018 06:29:00
- Zuletzt bearbeitet 26.06.2026 18:44:14
- Erkennungen
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Boot Version < 1.5.9
VMware ≫ Spring Boot Version 2.0.0 Update milestone1
VMware ≫ Spring Boot Version 2.0.0 Update milestone2
VMware ≫ Spring Boot Version 2.0.0 Update milestone3
VMware ≫ Spring Boot Version 2.0.0 Update milestone4
VMware ≫ Spring Boot Version 2.0.0 Update milestone5
Pivotal Software ≫ Spring Data Rest Version 3.0.0
Pivotal Software ≫ Spring Data Rest Version 3.0.0 Update m1
Pivotal Software ≫ Spring Data Rest Version 3.0.0 Update m2
Pivotal Software ≫ Spring Data Rest Version 3.0.0 Update m3
Pivotal Software ≫ Spring Data Rest Version 3.0.0 Update m4
VMware ≫ Spring Data Rest Version < 2.6.9
VMware ≫ Spring Data Rest Version 3.0.0 Update rc1
VMware ≫ Spring Data Rest Version 3.0.0 Update rc2
VMware ≫ Spring Data Rest Version 3.0.0 Update rc3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 74.53% | 0.995 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.securityfocus.com/bid/100948
https://access.redhat.com/errata/RHSA-2018:2405
https://pivotal.io/security/cve-2017-8046
https://www.exploit-db.com/exploits/44289/