CVE-2018-1258
highCVSS v3 Base Score
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
2.5%
Exploitation probability in 30 days
Top 17% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Confidentiality
High
Integrity
High
Availability
High
Vulnerability Report
Generated by CyberWatcher
Description
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
CWE
CWE-863Affected Products
pivotal software spring securityvmware spring frameworkoracle agile product lifecycle managementoracle application testing suiteoracle big data discoveryoracle communications converged application serveroracle communications diameter signaling routeroracle communications network integrityoracle communications performance intelligence centeroracle communications services gatekeeper