ZeroHour

CVE-2018-1273

KEV ransomwaremass

Unauthenticated RCE in VMware Tanzu Spring Data Commons

CISA: VMware Tanzu Spring Data Commons Property Binder Vulnerability

CVSS 3.1
9.8 critical
EPSS
97%p100
Published
()
KEV added
AI analysis

CVE-2018-1273 is a property binder flaw (CWE-94, improper neutralization of special elements leading to code injection) in Spring Data Commons, affecting versions 1.13.0 to 1.13.10, 2.0.0 to 2.0.5, and older unsupported releases. An unauthenticated remote attacker triggers it by sending specially crafted request parameters against Spring Data REST-backed HTTP resources or via Spring Data projection-based request payload binding. Successful exploitation yields remote code execution on the application host, reflected in the critical CVSS 3.1 score of 9.8 with network attack vector and no privileges or user interaction required. Any application built on the affected library and exposing the vulnerable binding paths is at risk, including deployments of Spring Data REST, Apache Ignite, and Oracle Financial Services Crime and Compliance Management Studio that bundle the library. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2022-03-25 with known ransomware use, EPSS rates a 97% probability of exploitation within 30 days (100th percentile), and related threat reporting shows active attacks against Java-based services, although no public PoC is catalogued in the source data.

What to do: Apply vendor updates per the CISA KEV required action: upgrade Spring Data Commons past the last-affected releases 1.13.10 and 2.0.5 (i.e., 1.13.11 or 2.0.6 and later) or to the latest supported release. Inventory internet-facing Java applications for Spring Data REST endpoints and projection-based payload binding, patch or restrict those paths, and review application logs for exploitation activity given the known ransomware use.

Affected
Pivotal Software (now VMware Tanzu/Broadcom) Spring Data Commons1.13.0 to 1.13.10, 2.0.0 to 2.0.5, and older unsupported versions
VMware Tanzu Spring Data Commons1.13.0 to 1.13.10, 2.0.0 to 2.0.5, and older unsupported versions (as named by CISA)
Pivotal Software (now VMware Tanzu/Broadcom) Spring Data REST
Apache Ignite
Oracle Financial Services Crime and Compliance Management Studio
Estimated exposure
massmillions of Java/Spring deployments embed the vulnerable library, with plausibly tens of thousands of directly internet-exposed exploitable endpoints — Spring Data Commons is a core component of the ubiquitously deployed Spring/Spring Boot enterprise Java ecosystem and is bundled into products such as Apache Ignite and Oracle Financial Services Crime and Compliance Management Studio, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

CISA Known Exploited Vulnerability
Affected
VMware Tanzu Spring Data Commons
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
broadcompivotal softwarevmwareapacheoracle
Products
spring data commons, spring data rest, ignite, financial services crime and compliance management studio
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news