6.5

CVE-2018-1257

Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.

Data is provided by the National Vulnerability Database (NVD)
VMwareSpring Framework Version < 4.3.17
VMwareSpring Framework Version >= 5.0.0 < 5.0.6
RedhatOpenshift Version-
OracleApplication Testing Suite Version12.5.0.3
OracleApplication Testing Suite Version13.1.0.1
OracleApplication Testing Suite Version13.2.0.1
OracleApplication Testing Suite Version13.3.0.1
OracleBig Data Discovery Version1.6.0
OracleFlexcube Private Banking Version2.0.0.0
OracleFlexcube Private Banking Version2.2.0.1
OracleFlexcube Private Banking Version12.0.1.0
OracleFlexcube Private Banking Version12.0.3.0
OracleFlexcube Private Banking Version12.1.0.0
OracleGoldengate For Big Data Version12.2.0.1
OracleGoldengate For Big Data Version12.3.1.1
OracleGoldengate For Big Data Version12.3.2.1
OracleHospitality Guest Access Version4.2.0
OracleHospitality Guest Access Version4.2.1
OraclePrimavera Gateway Version15.2
OraclePrimavera Gateway Version16.2
OraclePrimavera Gateway Version17.12
OracleRetail Order Broker Version5.1
OracleRetail Order Broker Version5.2
OracleRetail Order Broker Version15.0
OracleRetail Order Broker Version16.0
OracleTape Library Acsls Version8.4
OracleWeblogic Server Version10.3.6.0.0
OracleWeblogic Server Version12.1.3.0.0
OracleWeblogic Server Version12.2.1.3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.79% 0.82
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P