CVE-2018-1258

high VMware
CVSS v3 Base Score
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
2.5%
Exploitation probability in 30 days
Top 17% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Confidentiality
High
Integrity
High
Availability
High
Published: May 11, 2018 (3041 days ago)
Last Modified: August 25, 2026
Vendor: VMware
Source: NVD

Description

Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.

CWE

CWE-863

Affected Products

pivotal software spring securityvmware spring frameworkoracle agile product lifecycle managementoracle application testing suiteoracle big data discoveryoracle communications converged application serveroracle communications diameter signaling routeroracle communications network integrityoracle communications performance intelligence centeroracle communications services gatekeeper

References