CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2018-15756: spring framework 5.1.0; +40 more affected products

CVE-2018-15756. CVSS 3.1 base score 7.5 (HIGH, NVD). EPSS 0.09207 (percentile 0.95222), scored 2026-10-08.

Affected technology

spring framework · from 4.2.0 (inclusive), before 4.3.20 (exclusive)
vmware

spring framework · from 5.0.0 (inclusive), before 5.0.10 (exclusive)
vmware

spring framework · 5.1.0
vmware

agile product lifecycle management · 9.3.3
oracle

agile product lifecycle management · 9.3.4
oracle

agile product lifecycle management · 9.3.5
oracle

agile product lifecycle management · 9.3.6
oracle

communications brm - elastic charging engine · 11.3
oracle

communications brm - elastic charging engine · 12.0
oracle

communications converged application server - service controller · 6.0
oracle

communications converged application server - service controller · 6.1
oracle

communications diameter signaling router · 8.0.0
oracle

communications diameter signaling router · 8.1
oracle

communications diameter signaling router · 8.2
oracle

communications diameter signaling router · 8.2.1
oracle

communications element manager · 8.1.1
oracle

communications element manager · 8.2.0
oracle

communications element manager · 8.2.1
oracle

communications online mediation controller · 6.1
oracle

communications session report manager · 8.0.0
oracle

communications session report manager · 8.1.0
oracle

communications session report manager · 8.1.1
oracle

communications session report manager · 8.2.0
oracle

communications session report manager · 8.2.1
oracle

communications session route manager · 8.0.0
oracle

communications session route manager · 8.1.0
oracle

communications session route manager · 8.1.1
oracle

communications session route manager · 8.2.0
oracle

communications session route manager · 8.2.1
oracle

communications unified inventory management · 7.3
oracle

communications unified inventory management · 7.4.0
oracle

endeca information discovery integrator · 3.2.0
oracle

enterprise manager for fusion applications · 13.3.0.0
oracle

enterprise manager ops center · 12.3.3
oracle

financial services analytical applications infrastructure · from 8.0.2 (inclusive), through 8.0.8 (inclusive)
oracle

flexcube private banking · 12.0.1
oracle

flexcube private banking · 12.0.3
oracle

flexcube private banking · 12.1.0
oracle

goldengate application adapters · 12.3.2.1.0
oracle

healthcare master person index · 3.0
oracle

healthcare master person index · 4.0.2
oracle

identity manager connector · 9.0
oracle

insurance calculation engine · 9.7
oracle

insurance calculation engine · 10.0
oracle

insurance calculation engine · 10.1
oracle

insurance calculation engine · 10.2
oracle

insurance policy administration j2ee · 10.0
oracle

insurance policy administration j2ee · 10.1
oracle

insurance policy administration j2ee · 10.2
oracle

insurance policy administration j2ee · 10.2.0
oracle

insurance policy administration j2ee · 10.2.4
oracle

insurance policy administration j2ee · 11.0
oracle

insurance policy administration j2ee · 11.1.0
oracle

insurance policy administration j2ee · 11.2.0
oracle

insurance rules palette · 10.0
oracle

insurance rules palette · 10.1
oracle

insurance rules palette · 10.2
oracle

insurance rules palette · 10.2.0
oracle

insurance rules palette · 10.2.4
oracle

insurance rules palette · 11.0
oracle

insurance rules palette · 11.0.2
oracle

insurance rules palette · 11.1.0
oracle

insurance rules palette · 11.2.0
oracle

mysql enterprise monitor · through 4.0.12 (inclusive)
oracle

mysql enterprise monitor · from 8.0.0 (inclusive), through 8.0.20 (inclusive)
oracle

primavera analytics · 18.8
oracle

primavera gateway · 15.2
oracle

primavera gateway · 16.2
oracle

primavera gateway · 17.12
oracle

primavera gateway · 18.8.0
oracle

rapid planning · 12.1
oracle

rapid planning · 12.2
oracle

retail advanced inventory planning · 15.0
oracle

retail assortment planning · 15.0
oracle

retail assortment planning · 16.0
oracle

retail clearance optimization engine · 14.0.5
oracle

retail financial integration · 14.0
oracle

retail financial integration · 14.1
oracle

retail financial integration · 15.0
oracle

retail financial integration · 16.0
oracle

retail integration bus · 15.0
oracle

retail integration bus · 15.0.3
oracle

retail integration bus · 16.0
oracle

retail integration bus · 16.0.3
oracle

retail invoice matching · 12.0
oracle

retail invoice matching · 13.0
oracle

retail invoice matching · 13.1
oracle

retail invoice matching · 13.2
oracle

retail invoice matching · 14.0
oracle

retail invoice matching · 14.1
oracle

retail markdown optimization · 13.4.4
oracle

retail order broker · 5.1
oracle

retail order broker · 5.2
oracle

retail order broker · 15.0
oracle

retail order broker · 16.0
oracle

retail predictive application server · 14.0.3
oracle

retail predictive application server · 14.0.3.26
oracle

retail predictive application server · 14.1.3
oracle

retail predictive application server · 14.1.3.37
oracle

retail predictive application server · 15.0.3
oracle

retail predictive application server · 15.0.3.100
oracle

retail predictive application server · 16.0
oracle

retail predictive application server · 16.0.3
oracle

retail service backbone · 15.0
oracle

retail service backbone · 16.0
oracle

retail service backbone · 16.0.1
oracle

retail xstore point of service · 7.1
oracle

tape library acsls · 8.5
oracle

webcenter sites · 12.2.1.3.0
oracle

weblogic server · 10.3.6.0.0
oracle

weblogic server · 12.1.3.0.0
oracle

weblogic server · 12.2.1.3.0
oracle

weblogic server · 12.2.1.4.0
oracle

debian linux · 9.0
debian

Spring framework · 5.1, 5.0.0 through 5.0.9, 4.3 through 4.3.19
Pivotal

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could disrupt service under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CCR priority
32.3 /100 (P4)
CVSS 3.1
7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · NVD
EPSS
0.09207 · percentile 0.95222 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2018-15756.html