8.8

CVE-2018-1258

Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.

Data is provided by the National Vulnerability Database (NVD)
VMwareSpring Framework Version5.0.5
OracleAgile Plm Version9.3.3
OracleAgile Plm Version9.3.4
OracleAgile Plm Version9.3.5
OracleAgile Plm Version9.3.6
OracleApplication Testing Suite Version12.5.0.3
OracleApplication Testing Suite Version13.1.0.1
OracleApplication Testing Suite Version13.2.0.1
OracleApplication Testing Suite Version13.3.0.1
OracleBig Data Discovery Version1.6.0
OracleCommunications Network Integrity Version >= 7.3.2 <= 7.3.6
OracleEnterprise Repository Version11.1.1.7.0
OracleEnterprise Repository Version12.1.3.0.0
OracleGoldengate For Big Data Version12.2.0.1
OracleGoldengate For Big Data Version12.3.1.1
OracleGoldengate For Big Data Version12.3.2.1
OracleHospitality Guest Access Version4.2.0
OracleHospitality Guest Access Version4.2.1
OracleMicros Lucas Version2.9.5
OracleMysql Enterprise Monitor Version <= 8.0.2.8191
OracleRetail Back Office Version14.0
OracleRetail Back Office Version14.1
OracleRetail Central Office Version14.0
OracleRetail Central Office Version14.1
OracleRetail Integration Bus Version14.1.2
OracleTape Library Acsls Version8.4
OracleWeblogic Server Version10.3.6.0
OracleWeblogic Server Version12.1.3.0
OracleWeblogic Server Version12.2.1.2
OracleWeblogic Server Version12.2.1.3
NetappOncommand Insight Version-
NetappOncommand Unified Manager SwPlatformwindows Version >= 7.3
NetappOncommand Unified Manager SwPlatformvsphere Version >= 9.4
NetappSnapcenter Version-
RedhatFuse Version7.3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.16% 0.377
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

http://www.securitytracker.com/id/1041888
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/104222
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1041896
Third Party Advisory
VDB Entry