7.5
CVE-2018-15756
- EPSS 9.51%
- Veröffentlicht 18.10.2018 22:29:00
- Zuletzt bearbeitet 25.08.2026 16:28:27
- Erkennungen
DoS Attack via Range Requests
Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack. This vulnerability affects applications that depend on either spring-webmvc or spring-webflux. Such applications must also have a registration for serving static resources (e.g. JS, CSS, images, and others), or have an annotated controller that returns an org.springframework.core.io.Resource. Spring Boot applications that depend on spring-boot-starter-web or spring-boot-starter-webflux are ready to serve static resources out of the box and are therefore vulnerable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Framework Version >= 4.2.0 < 4.3.20
VMware ≫ Spring Framework Version >= 5.0.0 < 5.0.10
VMware ≫ Spring Framework Version 5.1.0
Oracle ≫ Agile Product Lifecycle Management Version 9.3.3
Oracle ≫ Agile Product Lifecycle Management Version 9.3.4
Oracle ≫ Agile Product Lifecycle Management Version 9.3.5
Oracle ≫ Agile Product Lifecycle Management Version 9.3.6
Oracle ≫ Communications Brm - Elastic Charging Engine Version 11.3
Oracle ≫ Communications Brm - Elastic Charging Engine Version 12.0
Oracle ≫ Communications Diameter Signaling Router Version 8.0.0
Oracle ≫ Communications Diameter Signaling Router Version 8.1
Oracle ≫ Communications Diameter Signaling Router Version 8.2
Oracle ≫ Communications Diameter Signaling Router Version 8.2.1
Oracle ≫ Communications Element Manager Version 8.1.1
Oracle ≫ Communications Element Manager Version 8.2.0
Oracle ≫ Communications Element Manager Version 8.2.1
Oracle ≫ Communications Online Mediation Controller Version 6.1
Oracle ≫ Communications Session Report Manager Version 8.0.0
Oracle ≫ Communications Session Report Manager Version 8.1.0
Oracle ≫ Communications Session Report Manager Version 8.1.1
Oracle ≫ Communications Session Report Manager Version 8.2.0
Oracle ≫ Communications Session Report Manager Version 8.2.1
Oracle ≫ Communications Session Route Manager Version 8.0.0
Oracle ≫ Communications Session Route Manager Version 8.1.0
Oracle ≫ Communications Session Route Manager Version 8.1.1
Oracle ≫ Communications Session Route Manager Version 8.2.0
Oracle ≫ Communications Session Route Manager Version 8.2.1
Oracle ≫ Communications Unified Inventory Management Version 7.3
Oracle ≫ Communications Unified Inventory Management Version 7.4.0
Oracle ≫ Endeca Information Discovery Integrator Version 3.2.0
Oracle ≫ Enterprise Manager For Fusion Applications Version 13.3.0.0
Oracle ≫ Enterprise Manager Ops Center Version 12.3.3
Oracle ≫ Financial Services Analytical Applications Infrastructure Version >= 8.0.2 <= 8.0.8
Oracle ≫ Flexcube Private Banking Version 12.0.1
Oracle ≫ Flexcube Private Banking Version 12.0.3
Oracle ≫ Flexcube Private Banking Version 12.1.0
Oracle ≫ Goldengate Application Adapters Version 12.3.2.1.0
Oracle ≫ Healthcare Master Person Index Version 3.0
Oracle ≫ Healthcare Master Person Index Version 4.0.2
Oracle ≫ Identity Manager Connector Version 9.0
Oracle ≫ Insurance Calculation Engine Version 9.7
Oracle ≫ Insurance Calculation Engine Version 10.0
Oracle ≫ Insurance Calculation Engine Version 10.1
Oracle ≫ Insurance Calculation Engine Version 10.2
Oracle ≫ Insurance Policy Administration J2ee Version 10.0
Oracle ≫ Insurance Policy Administration J2ee Version 10.1
Oracle ≫ Insurance Policy Administration J2ee Version 10.2
Oracle ≫ Insurance Policy Administration J2ee Version 10.2.0
Oracle ≫ Insurance Policy Administration J2ee Version 10.2.4
Oracle ≫ Insurance Policy Administration J2ee Version 11.0
Oracle ≫ Insurance Policy Administration J2ee Version 11.1.0
Oracle ≫ Insurance Policy Administration J2ee Version 11.2.0
Oracle ≫ Insurance Rules Palette Version 10.0
Oracle ≫ Insurance Rules Palette Version 10.1
Oracle ≫ Insurance Rules Palette Version 10.2
Oracle ≫ Insurance Rules Palette Version 10.2.0
Oracle ≫ Insurance Rules Palette Version 10.2.4
Oracle ≫ Insurance Rules Palette Version 11.0
Oracle ≫ Insurance Rules Palette Version 11.0.2
Oracle ≫ Insurance Rules Palette Version 11.1.0
Oracle ≫ Insurance Rules Palette Version 11.2.0
Oracle ≫ Mysql Enterprise Monitor Version <= 4.0.12
Oracle ≫ Mysql Enterprise Monitor Version >= 8.0.0 <= 8.0.20
Oracle ≫ Primavera Analytics Version 18.8
Oracle ≫ Primavera Gateway Version 15.2
Oracle ≫ Primavera Gateway Version 16.2
Oracle ≫ Primavera Gateway Version 17.12
Oracle ≫ Primavera Gateway Version 18.8.0
Oracle ≫ Rapid Planning Version 12.1
Oracle ≫ Rapid Planning Version 12.2
Oracle ≫ Retail Advanced Inventory Planning Version 15.0
Oracle ≫ Retail Assortment Planning Version 15.0
Oracle ≫ Retail Assortment Planning Version 16.0
Oracle ≫ Retail Clearance Optimization Engine Version 14.0.5
Oracle ≫ Retail Financial Integration Version 14.0
Oracle ≫ Retail Financial Integration Version 14.1
Oracle ≫ Retail Financial Integration Version 15.0
Oracle ≫ Retail Financial Integration Version 16.0
Oracle ≫ Retail Integration Bus Version 15.0
Oracle ≫ Retail Integration Bus Version 15.0.3
Oracle ≫ Retail Integration Bus Version 16.0
Oracle ≫ Retail Integration Bus Version 16.0.3
Oracle ≫ Retail Invoice Matching Version 12.0
Oracle ≫ Retail Invoice Matching Version 13.0
Oracle ≫ Retail Invoice Matching Version 13.1
Oracle ≫ Retail Invoice Matching Version 13.2
Oracle ≫ Retail Invoice Matching Version 14.0
Oracle ≫ Retail Invoice Matching Version 14.1
Oracle ≫ Retail Markdown Optimization Version 13.4.4
Oracle ≫ Retail Order Broker Version 5.1
Oracle ≫ Retail Order Broker Version 5.2
Oracle ≫ Retail Order Broker Version 15.0
Oracle ≫ Retail Order Broker Version 16.0
Oracle ≫ Retail Predictive Application Server Version 14.0.3
Oracle ≫ Retail Predictive Application Server Version 14.0.3.26
Oracle ≫ Retail Predictive Application Server Version 14.1.3
Oracle ≫ Retail Predictive Application Server Version 14.1.3.37
Oracle ≫ Retail Predictive Application Server Version 15.0.3
Oracle ≫ Retail Predictive Application Server Version 15.0.3.100
Oracle ≫ Retail Predictive Application Server Version 16.0
Oracle ≫ Retail Predictive Application Server Version 16.0.3
Oracle ≫ Retail Service Backbone Version 15.0
Oracle ≫ Retail Service Backbone Version 16.0
Oracle ≫ Retail Service Backbone Version 16.0.1
Oracle ≫ Retail Xstore Point Of Service Version 7.1
Oracle ≫ Tape Library Acsls Version 8.5
Oracle ≫ Webcenter Sites Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 10.3.6.0.0
Oracle ≫ Weblogic Server Version 12.1.3.0.0
Oracle ≫ Weblogic Server Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 12.2.1.4.0
Debian ≫ Debian Linux Version 9.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 9.51% | 0.948 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
| EMC | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuoct2021.html
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html
http://www.securityfocus.com/bid/105703
https://pivotal.io/security/cve-2018-15756
https://lists.apache.org/thread.html/339fd112517e4873695b5115b96acdddbfc8f83b10598528d37c7d12%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/77886fec378ee6064debb1efb6b464a4a0173b2ff0d151ed86d3a228%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/7b156ee50ba3ecce87b33c06bf7a749d84ffee55e69bfb5eca88fcc3%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/8a1fe70534fc52ff5c9db5ac29c55657f802cbefd7e9d9850c7052bd%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/a3071e11c6fbd593022074ec1b4693f6d948c2b02cfa4a5d854aed68%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/bb354962cb51fff65740d5fb1bc2aac56af577c06244b57c36f98e4d%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/d6a84f52db89804b0ad965f3ea2b24bb880edee29107a1c5069cc3dd%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/efaa52b0aa67aae7cbd9e6ef96945387e422d7ce0e65434570a37b1d%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/f8905507a2c94af6b08b72d7be0c4b8c6660e585f00abfafeccc86bc%40%3Cissues.activemq.apache.org%3E