Description
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected products
- debian / debian_linux9.0 – 9.0
- oracle / agile_product_lifecycle_management9.3.5 – 9.3.5
- oracle / agile_product_lifecycle_management9.3.6 – 9.3.6
- oracle / agile_product_lifecycle_management9.3.3 – 9.3.3
- oracle / agile_product_lifecycle_management9.3.4 – 9.3.4
- oracle / Application Testing Suite13.3.0.1 – 13.3.0.1
- oracle / Application Testing Suite13.1.0.1 – 13.1.0.1
- oracle / Application Testing Suite13.2.0.1 – 13.2.0.1
- oracle / Application Testing Suite12.5.0.3 – 12.5.0.3
- oracle / communications_diameter_signaling_router8.3
- oracle / communications_network_integrity7.3.2 – 7.3.6
- oracle / communications_online_mediation_controller6.1 – 6.1
- oracle / communications_performance_intelligence_center10.2.1
- oracle / communications_services_gatekeeper6.1.0.4.0
- oracle / communications_unified_inventory_management7.4.0 – 7.4.0
- oracle / communications_unified_inventory_management7.3.4 – 7.3.4
- oracle / communications_unified_inventory_management7.3.5 – 7.3.5
- oracle / communications_unified_inventory_management7.3.2 – 7.3.2
- oracle / endeca_information_discovery_integrator3.2.0 – 3.2.0
- oracle / endeca_information_discovery_integrator3.1.0 – 3.1.0
- oracle / enterprise_manager_base_platform13.3.0.0.0 – 13.3.0.0.0
- oracle / enterprise_manager_base_platform12.1.0.5.0 – 12.1.0.5.0
- oracle / enterprise_manager_base_platform13.2.0.0.0 – 13.2.0.0.0
- oracle / enterprise_manager_for_mysql_database13.2 – 13.2
- oracle / enterprise_manager_ops_center12.3.3 – 12.3.3
- oracle / healthcare_master_person_index3.0 – 3.0
- oracle / healthcare_master_person_index4.0 – 4.0
- oracle / health_sciences_information_manager3.0 – 3.0
- oracle / hospitality_guest_access4.2.1 – 4.2.1
- oracle / hospitality_guest_access4.2.0 – 4.2.0
- oracle / insurance_calculation_engine11.0.0 – 11.3.1
- oracle / insurance_calculation_engine10.2 – 10.2
- oracle / insurance_rules_palette10.2 – 10.2
- oracle / insurance_rules_palette10.0 – 10.0
- oracle / micros_lucas2.9.5 – 2.9.5
- oracle / MySQL Enterprise Monitor3.4.9.4237
- oracle / primavera_p6_enterprise_project_portfolio_management18.8 – 18.8
- oracle / retail_advanced_inventory_planning15.0 – 15.0
- oracle / retail_assortment_planning14.1 – 14.1
- oracle / retail_assortment_planning16.0 – 16.0
- oracle / retail_assortment_planning15.0 – 15.0
- oracle / retail_clearance_optimization_engine14.0.5 – 14.0.5
- oracle / retail_customer_insights16.0 – 16.0
- oracle / retail_customer_insights15.0 – 15.0
- oracle / retail_financial_integration16.0 – 16.0
- oracle / retail_financial_integration14.1 – 14.1
- oracle / retail_financial_integration15.0 – 15.0
- oracle / retail_financial_integration13.2 – 13.2
- oracle / retail_financial_integration14.0 – 14.0
- oracle / retail_integration_bus14.1.2 – 14.1.2
- oracle / retail_markdown_optimization13.4.4 – 13.4.4
- oracle / retail_predictive_application_server16.0 – 16.0
- oracle / retail_predictive_application_server14.1.3.37 – 14.1.3.37
- oracle / retail_predictive_application_server15.0.3..100 – 15.0.3..100
- oracle / retail_predictive_application_server14.0.3.26 – 14.0.3.26
- oracle / retail_xstore_point_of_service7.1 – 7.1
- oracle / utilities_network_management_system1.12.0.3 – 1.12.0.3
- oracle / weblogic_server10.3.6.0.0 – 10.3.6.0.0
- oracle / weblogic_server12.2.1.3.0 – 12.2.1.3.0
- oracle / weblogic_server12.1.3.0.0 – 12.1.3.0.0
- Pivotal / Spring Framework4.3.x – 4.3.18
- Pivotal / Spring Framework5.0.x – 5.0.7
- VMware / Spring Framework4.3.18
References
- MISChttp://www.securityfocus.com/bid/107984
- VENDOR_ADVISORYhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpujul2020.html
- VENDOR_ADVISORYhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- VENDOR_ADVISORYhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- VENDOR_ADVISORYhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpujan2020.html
- MISChttps://pivotal.io/security/cve-2018-11039
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2021/04/msg00022.html
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpuoct2021.html
Updated 17m ago · 8 sources