Vulnerability Intelligence Report
VMware Tanzu Spring Data Commons Property Binder Vulnerability
CVE-2018-1273
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:95.71%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-94 ↗CWE-94 - Code Injection
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Spring by Pivotal | Spring Framework | Versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
95.715%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Dell · Vendor · USA |
| Reserved | 2017-12-06T00:00:00 |
| Published | 2018-04-11T13:00:00 |
| Patch Date | 2018-04-10 |
| Last Updated | 2026-08-26T03:56:07 |
Community Chatter & Buzz