7.5

CVE-2018-15756

DoS Attack via Range Requests

Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack. This vulnerability affects applications that depend on either spring-webmvc or spring-webflux. Such applications must also have a registration for serving static resources (e.g. JS, CSS, images, and others), or have an annotated controller that returns an org.springframework.core.io.Resource. Spring Boot applications that depend on spring-boot-starter-web or spring-boot-starter-webflux are ready to serve static resources out of the box and are therefore vulnerable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Framework Version >= 4.2.0 < 4.3.20
VMware ≫ Spring Framework Version >= 5.0.0 < 5.0.10
VMware ≫ Spring Framework Version 5.1.0
Oracle ≫ Flexcube Private Banking Version 12.0.1
Oracle ≫ Flexcube Private Banking Version 12.0.3
Oracle ≫ Flexcube Private Banking Version 12.1.0
Oracle ≫ Goldengate Application Adapters Version 12.3.2.1.0
Oracle ≫ Insurance Rules Palette Version 10.0
Oracle ≫ Insurance Rules Palette Version 10.1
Oracle ≫ Insurance Rules Palette Version 10.2
Oracle ≫ Insurance Rules Palette Version 10.2.0
Oracle ≫ Insurance Rules Palette Version 10.2.4
Oracle ≫ Insurance Rules Palette Version 11.0
Oracle ≫ Insurance Rules Palette Version 11.0.2
Oracle ≫ Insurance Rules Palette Version 11.1.0
Oracle ≫ Insurance Rules Palette Version 11.2.0
Oracle ≫ Mysql Enterprise Monitor Version <= 4.0.12
Oracle ≫ Mysql Enterprise Monitor Version >= 8.0.0 <= 8.0.20
Oracle ≫ Primavera Analytics Version 18.8
Oracle ≫ Primavera Gateway Version 15.2
Oracle ≫ Primavera Gateway Version 16.2
Oracle ≫ Primavera Gateway Version 17.12
Oracle ≫ Primavera Gateway Version 18.8.0
Oracle ≫ Rapid Planning Version 12.1
Oracle ≫ Rapid Planning Version 12.2
Oracle ≫ Retail Integration Bus Version 15.0
Oracle ≫ Retail Integration Bus Version 15.0.3
Oracle ≫ Retail Integration Bus Version 16.0
Oracle ≫ Retail Integration Bus Version 16.0.3
Oracle ≫ Retail Invoice Matching Version 12.0
Oracle ≫ Retail Invoice Matching Version 13.0
Oracle ≫ Retail Invoice Matching Version 13.1
Oracle ≫ Retail Invoice Matching Version 13.2
Oracle ≫ Retail Invoice Matching Version 14.0
Oracle ≫ Retail Invoice Matching Version 14.1
Oracle ≫ Retail Order Broker Version 5.1
Oracle ≫ Retail Order Broker Version 5.2
Oracle ≫ Retail Order Broker Version 15.0
Oracle ≫ Retail Order Broker Version 16.0
Oracle ≫ Retail Service Backbone Version 15.0
Oracle ≫ Retail Service Backbone Version 16.0
Oracle ≫ Retail Service Backbone Version 16.0.1
Oracle ≫ Tape Library Acsls Version 8.5
Oracle ≫ Webcenter Sites Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 10.3.6.0.0
Oracle ≫ Weblogic Server Version 12.1.3.0.0
Oracle ≫ Weblogic Server Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 12.2.1.4.0
Debian ≫ Debian Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.51% 0.948
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
EMC 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.oracle.com/security-alerts/cpujan2020.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html
Patch
Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Third Party Advisory
Not Applicable
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
Patch
Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html
Patch
Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Patch
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/105703
Third Party Advisory
VDB Entry
URL Repurposed
https://pivotal.io/security/cve-2018-15756
Vendor Advisory
https://lists.apache.org/thread.html/339fd112517e4873695b5115b96acdddbfc8f83b10598528d37c7d12%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/77886fec378ee6064debb1efb6b464a4a0173b2ff0d151ed86d3a228%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/7b156ee50ba3ecce87b33c06bf7a749d84ffee55e69bfb5eca88fcc3%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/8a1fe70534fc52ff5c9db5ac29c55657f802cbefd7e9d9850c7052bd%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/a3071e11c6fbd593022074ec1b4693f6d948c2b02cfa4a5d854aed68%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/bb354962cb51fff65740d5fb1bc2aac56af577c06244b57c36f98e4d%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/d6a84f52db89804b0ad965f3ea2b24bb880edee29107a1c5069cc3dd%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/efaa52b0aa67aae7cbd9e6ef96945387e422d7ce0e65434570a37b1d%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/f8905507a2c94af6b08b72d7be0c4b8c6660e585f00abfafeccc86bc%40%3Cissues.activemq.apache.org%3E