Get real-time updates on Telegram
CVE-2018-15756: spring framework 5.1.0; +40 more affected products
CVE-2018-15756. CVSS 3.1 base score 7.5 (HIGH, NVD). EPSS 0.09207 (percentile 0.95222), scored 2026-10-08.
Affected technology
spring framework · from 4.2.0 (inclusive), before 4.3.20 (exclusive)
vmware
spring framework · from 5.0.0 (inclusive), before 5.0.10 (exclusive)
vmware
spring framework · 5.1.0
vmware
agile product lifecycle management · 9.3.3
oracle
agile product lifecycle management · 9.3.4
oracle
agile product lifecycle management · 9.3.5
oracle
agile product lifecycle management · 9.3.6
oracle
communications brm - elastic charging engine · 11.3
oracle
communications brm - elastic charging engine · 12.0
oracle
communications converged application server - service controller · 6.0
oracle
communications converged application server - service controller · 6.1
oracle
communications diameter signaling router · 8.0.0
oracle
communications diameter signaling router · 8.1
oracle
communications diameter signaling router · 8.2
oracle
communications diameter signaling router · 8.2.1
oracle
communications element manager · 8.1.1
oracle
communications element manager · 8.2.0
oracle
communications element manager · 8.2.1
oracle
communications online mediation controller · 6.1
oracle
communications session report manager · 8.0.0
oracle
communications session report manager · 8.1.0
oracle
communications session report manager · 8.1.1
oracle
communications session report manager · 8.2.0
oracle
communications session report manager · 8.2.1
oracle
communications session route manager · 8.0.0
oracle
communications session route manager · 8.1.0
oracle
communications session route manager · 8.1.1
oracle
communications session route manager · 8.2.0
oracle
communications session route manager · 8.2.1
oracle
communications unified inventory management · 7.3
oracle
communications unified inventory management · 7.4.0
oracle
endeca information discovery integrator · 3.2.0
oracle
enterprise manager for fusion applications · 13.3.0.0
oracle
enterprise manager ops center · 12.3.3
oracle
financial services analytical applications infrastructure · from 8.0.2 (inclusive), through 8.0.8 (inclusive)
oracle
flexcube private banking · 12.0.1
oracle
flexcube private banking · 12.0.3
oracle
flexcube private banking · 12.1.0
oracle
goldengate application adapters · 12.3.2.1.0
oracle
healthcare master person index · 3.0
oracle
healthcare master person index · 4.0.2
oracle
identity manager connector · 9.0
oracle
insurance calculation engine · 9.7
oracle
insurance calculation engine · 10.0
oracle
insurance calculation engine · 10.1
oracle
insurance calculation engine · 10.2
oracle
insurance policy administration j2ee · 10.0
oracle
insurance policy administration j2ee · 10.1
oracle
insurance policy administration j2ee · 10.2
oracle
insurance policy administration j2ee · 10.2.0
oracle
insurance policy administration j2ee · 10.2.4
oracle
insurance policy administration j2ee · 11.0
oracle
insurance policy administration j2ee · 11.1.0
oracle
insurance policy administration j2ee · 11.2.0
oracle
insurance rules palette · 10.0
oracle
insurance rules palette · 10.1
oracle
insurance rules palette · 10.2
oracle
insurance rules palette · 10.2.0
oracle
insurance rules palette · 10.2.4
oracle
insurance rules palette · 11.0
oracle
insurance rules palette · 11.0.2
oracle
insurance rules palette · 11.1.0
oracle
insurance rules palette · 11.2.0
oracle
mysql enterprise monitor · through 4.0.12 (inclusive)
oracle
mysql enterprise monitor · from 8.0.0 (inclusive), through 8.0.20 (inclusive)
oracle
primavera analytics · 18.8
oracle
primavera gateway · 15.2
oracle
primavera gateway · 16.2
oracle
primavera gateway · 17.12
oracle
primavera gateway · 18.8.0
oracle
rapid planning · 12.1
oracle
rapid planning · 12.2
oracle
retail advanced inventory planning · 15.0
oracle
retail assortment planning · 15.0
oracle
retail assortment planning · 16.0
oracle
retail clearance optimization engine · 14.0.5
oracle
retail financial integration · 14.0
oracle
retail financial integration · 14.1
oracle
retail financial integration · 15.0
oracle
retail financial integration · 16.0
oracle
retail integration bus · 15.0
oracle
retail integration bus · 15.0.3
oracle
retail integration bus · 16.0
oracle
retail integration bus · 16.0.3
oracle
retail invoice matching · 12.0
oracle
retail invoice matching · 13.0
oracle
retail invoice matching · 13.1
oracle
retail invoice matching · 13.2
oracle
retail invoice matching · 14.0
oracle
retail invoice matching · 14.1
oracle
retail markdown optimization · 13.4.4
oracle
retail order broker · 5.1
oracle
retail order broker · 5.2
oracle
retail order broker · 15.0
oracle
retail order broker · 16.0
oracle
retail predictive application server · 14.0.3
oracle
retail predictive application server · 14.0.3.26
oracle
retail predictive application server · 14.1.3
oracle
retail predictive application server · 14.1.3.37
oracle
retail predictive application server · 15.0.3
oracle
retail predictive application server · 15.0.3.100
oracle
retail predictive application server · 16.0
oracle
retail predictive application server · 16.0.3
oracle
retail service backbone · 15.0
oracle
retail service backbone · 16.0
oracle
retail service backbone · 16.0.1
oracle
retail xstore point of service · 7.1
oracle
tape library acsls · 8.5
oracle
webcenter sites · 12.2.1.3.0
oracle
weblogic server · 10.3.6.0.0
oracle
weblogic server · 12.1.3.0.0
oracle
weblogic server · 12.2.1.3.0
oracle
weblogic server · 12.2.1.4.0
oracle
debian linux · 9.0
debian
Spring framework · 5.1, 5.0.0 through 5.0.9, 4.3 through 4.3.19
Pivotal
Component: Not specified by the source
Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
The source reports that an attacker could disrupt service under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high.
- CCR priority
- 32.3 /100 (P4)
- CVSS 3.1
- 7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · NVD
- EPSS
- 0.09207 · percentile 0.95222 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2018-15756.html