7.5
CVE-2018-11040
- EPSS 3.24%
- Veröffentlicht 25.06.2018 15:29:00
- Zuletzt bearbeitet 08.10.2026 22:16:44
- Erkennungen
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Framework Version < 4.3.18
VMware ≫ Spring Framework Version >= 5.0.0 < 5.0.7
Oracle ≫ Agile Product Lifecycle Management Version 9.3.3
Oracle ≫ Agile Product Lifecycle Management Version 9.3.4
Oracle ≫ Agile Product Lifecycle Management Version 9.3.5
Oracle ≫ Application Testing Suite Version 12.5.0.3
Oracle ≫ Application Testing Suite Version 13.1.0.1
Oracle ≫ Application Testing Suite Version 13.2.0.1
Oracle ≫ Application Testing Suite Version 13.3.0.1
Oracle ≫ Communications Network Integrity Version >= 7.3.2 <= 7.3.6
Oracle ≫ Communications Online Mediation Controller Version 6.1
Oracle ≫ Communications Services Gatekeeper Version < 6.1.0.4.0
Oracle ≫ Communications Unified Inventory Management Version 7.3.2
Oracle ≫ Communications Unified Inventory Management Version 7.3.4
Oracle ≫ Communications Unified Inventory Management Version 7.3.5
Oracle ≫ Communications Unified Inventory Management Version 7.4.0
Oracle ≫ Endeca Information Discovery Integrator Version 3.1.0
Oracle ≫ Endeca Information Discovery Integrator Version 3.2.0
Oracle ≫ Enterprise Manager Version 13.2 SwPlatform mysql
Oracle ≫ Enterprise Manager Ops Center Version 12.3.3
Oracle ≫ Flexcube Private Banking Version 2.0.0.0
Oracle ≫ Flexcube Private Banking Version 2.2.0.1
Oracle ≫ Flexcube Private Banking Version 12.0.1.0
Oracle ≫ Flexcube Private Banking Version 12.0.3.0
Oracle ≫ Flexcube Private Banking Version 12.1.0.0
Oracle ≫ Healthcare Master Person Index Version 3.0
Oracle ≫ Healthcare Master Person Index Version 4.0
Oracle ≫ Hospitality Guest Access Version 4.2.0
Oracle ≫ Hospitality Guest Access Version 4.2.1
Oracle ≫ Insurance Calculation Engine Version >= 11.0.0 <= 11.3.1
Oracle ≫ Insurance Rules Palette Version 10.0
Oracle ≫ Insurance Rules Palette Version 10.2
Oracle ≫ Micros Lucas Version 2.9.5
Oracle ≫ Mysql Enterprise Monitor Version <= 3.4.9.4237
Oracle ≫ Mysql Enterprise Monitor Version >= 3.4.10 <= 4.0.6.5281
Oracle ≫ Mysql Enterprise Monitor Version >= 4.0.7 <= 8.0.2.8191
Oracle ≫ Product Lifecycle Management Version 9.3.6
Oracle ≫ Retail Advanced Inventory Planning Version 15.0
Oracle ≫ Retail Clearance Optimization Engine Version 14.0.5
Oracle ≫ Retail Customer Insights Version 15.0
Oracle ≫ Retail Customer Insights Version 16.0
Oracle ≫ Retail Markdown Optimization Version 13.4.4
Oracle ≫ Retail Predictive Application Server Version 14.0.3.26
Oracle ≫ Retail Predictive Application Server Version 14.1.3.37
Oracle ≫ Retail Predictive Application Server Version 15.0.3.100
Oracle ≫ Retail Predictive Application Server Version 16.0
Oracle ≫ Retail Service Backbone Version 16.0.1
Oracle ≫ Retail Xstore Point Of Service Version 7.1
Oracle ≫ Utilities Network Management System Version 1.12.0.3
Oracle ≫ Weblogic Server Version 12.2.1.3.0
Debian ≫ Debian Linux Version 9.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.24% | 0.867 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-829 Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpuoct2021.html
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html
https://pivotal.io/security/cve-2018-11040