CVE-2018-11039

medium VMware
CVSS v3 Base Score
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
2.7%
Exploitation probability in 30 days
Top 15% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
None
Availability
None
Published: June 25, 2018 (2996 days ago)
Last Modified: August 25, 2026
Vendor: VMware
Source: NVD

Description

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CWE

NVD-CWE-noinfo

Affected Products

vmware spring frameworkoracle agile product lifecycle managementoracle application testing suiteoracle communications diameter signaling routeroracle communications network integrityoracle communications online mediation controlleroracle communications performance intelligence centeroracle communications services gatekeeperoracle communications unified inventory managementoracle endeca information discovery integrator

References