HackerFeeds
All CVEs

CVE-2018-1273

CRITICAL9.8
CISA KEV

Published 2018-04-11 · Updated 2026-06-26 · Source security_alert@emc.com

Description

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CWE-94

CISA Known-Exploited Vulnerability

Product: VMware TanzuSpring Data Commons

Name: VMware Tanzu Spring Data Commons Property Binder Vulnerability

Date added: 2022-03-25 · Due: 2022-04-15

USED IN RANSOMWARE

Required action: Apply updates per vendor instructions.

View on NVD