{"id":"CVE-2018-1270","title":"Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging…","summary":"Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-94","CWE-358"],"vendor":"vmware","product":"spring_framework","affected":["spring_framework < 4.3.16","spring_framework >= 5.0.0, < 5.0.5","application_testing_suite = 12.5.0.3","application_testing_suite = 13.1.0.1","application_testing_suite = 13.2.0.1","application_testing_suite = 13.3.0.1","big_data_discovery = 1.6.0","communications_converged_application_server < 7.0.0.1","communications_diameter_signaling_router < 8.3","communications_performance_intelligence_center < 10.2.1","communications_services_gatekeeper < 6.1.0.4.0","enterprise_manager_ops_center = 12.2.2","enterprise_manager_ops_center = 12.3.3","goldengate_for_big_data = 12.2.0.1","goldengate_for_big_data = 12.3.1.1","goldengate_for_big_data = 12.3.2.1","health_sciences_information_manager = 3.0","healthcare_master_person_index = 3.0","healthcare_master_person_index = 4.0","insurance_calculation_engine = 10.1.1","insurance_calculation_engine = 10.2","insurance_calculation_engine = 10.2.1","insurance_rules_palette = 10.0","insurance_rules_palette = 10.1","insurance_rules_palette = 10.2","insurance_rules_palette = 11.0","insurance_rules_palette = 11.1","primavera_gateway = 15.2","primavera_gateway = 16.2","primavera_gateway = 17.12","retail_back_office = 14.0","retail_back_office = 14.1","retail_central_office = 14.0","retail_central_office = 14.1","retail_customer_insights = 15.0","retail_customer_insights = 16.0","retail_integration_bus = 14.0.1","retail_integration_bus = 14.0.2","retail_integration_bus = 14.0.3","retail_integration_bus = 14.0.4","retail_integration_bus = 14.1.1","retail_integration_bus = 14.1.2","retail_integration_bus = 14.1.3","retail_integration_bus = 15.0.0.1","retail_integration_bus = 15.0.1","retail_integration_bus = 15.0.2","retail_integration_bus = 16.0","retail_integration_bus = 16.0.1","retail_integration_bus = 16.0.2","retail_open_commerce_platform = 5.3.0","retail_open_commerce_platform = 6.0.0","retail_open_commerce_platform = 6.0.1","retail_order_broker = 5.1","retail_order_broker = 5.2","retail_order_broker = 15.0","retail_order_broker = 16.0","retail_point-of-sale = 14.0","retail_point-of-sale = 14.1","retail_predictive_application_server = 14.0","retail_predictive_application_server = 14.1","retail_predictive_application_server = 15.0","retail_predictive_application_server = 16.0","retail_returns_management = 14.0","retail_returns_management = 14.1","retail_xstore_point_of_service = 7.1","service_architecture_leveraging_tuxedo = 12.1.3.0.0","service_architecture_leveraging_tuxedo = 12.2.2.0.0","tape_library_acsls = 8.4","fuse = 1.0.0","debian_linux = 9.0"],"patched":["spring_framework 5.0.5","communications_converged_application_server 7.0.0.1","communications_diameter_signaling_router 8.3","communications_performance_intelligence_center 10.2.1","communications_services_gatekeeper 6.1.0.4.0"],"published":"2018-04-06","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:16:46.473","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-1270","references":[{"url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","label":"security_alert@emc.com"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","label":"security_alert@emc.com"},{"url":"http://www.securityfocus.com/bid/103696","label":"security_alert@emc.com"},{"url":"https://access.redhat.com/errata/RHSA-2018:2939","label":"security_alert@emc.com"},{"url":"https://lists.apache.org/thread.html/4ed49b103f64a0cecb38064f26cbf1389afc12124653da2d35166dbe%40%3Cissues.activemq.apache.org%3E","label":"security_alert@emc.com"},{"url":"https://lists.apache.org/thread.html/6d3d34adcf3dfc48e36342aa1f18ce3c20bb8e4c458a97508d5bfed1%40%3Cissues.activemq.apache.org%3E","label":"security_alert@emc.com"},{"url":"https://lists.apache.org/thread.html/ab825fcade0b49becfa30235b3d54f4a51bb74ea96b6c9adb5d1378c%40%3Cissues.activemq.apache.org%3E","label":"security_alert@emc.com"},{"url":"https://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369%40%3Cissues.activemq.apache.org%3E","label":"security_alert@emc.com"},{"url":"https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","label":"security_alert@emc.com"},{"url":"https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html","label":"security_alert@emc.com"},{"url":"https://pivotal.io/security/cve-2018-1270","label":"security_alert@emc.com"},{"url":"https://www.exploit-db.com/exploits/44796/","label":"security_alert@emc.com"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"security_alert@emc.com"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"security_alert@emc.com"},{"url":"https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","label":"security_alert@emc.com"},{"url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","label":"security_alert@emc.com"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/103696","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2018:2939","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/4ed49b103f64a0cecb38064f26cbf1389afc12124653da2d35166dbe%40%3Cissues.activemq.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/6d3d34adcf3dfc48e36342aa1f18ce3c20bb8e4c458a97508d5bfed1%40%3Cissues.activemq.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/ab825fcade0b49becfa30235b3d54f4a51bb74ea96b6c9adb5d1378c%40%3Cissues.activemq.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369%40%3Cissues.activemq.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://pivotal.io/security/cve-2018-1270","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.exploit-db.com/exploits/44796/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.77476,"epssPercentile":0.99551,"exploits":{"github":4,"githubRepos":["https://github.com/CaledoniaProject/CVE-2018-1270","https://github.com/Tom4t0/CVE-2018-1270_EXP","https://github.com/tafamace/CVE-2018-1270"],"checkedAt":"2026-10-08T23:17:21.732Z"},"exploitAvailable":true,"ingestedAt":"2026-10-08T23:16:47.287Z","slug":"CVE-2018-1270","body":"## Overview\n\nSpring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.\n\n## Affected\n\n- `spring_framework < 4.3.16`\n- `spring_framework >= 5.0.0, < 5.0.5`\n- `application_testing_suite = 12.5.0.3`\n- `application_testing_suite = 13.1.0.1`\n- `application_testing_suite = 13.2.0.1`\n- `application_testing_suite = 13.3.0.1`\n- `big_data_discovery = 1.6.0`\n- `communications_converged_application_server < 7.0.0.1`\n- `communications_diameter_signaling_router < 8.3`\n- `communications_performance_intelligence_center < 10.2.1`\n- `communications_services_gatekeeper < 6.1.0.4.0`\n- `enterprise_manager_ops_center = 12.2.2`\n- `enterprise_manager_ops_center = 12.3.3`\n- `goldengate_for_big_data = 12.2.0.1`\n- `goldengate_for_big_data = 12.3.1.1`\n- `goldengate_for_big_data = 12.3.2.1`\n- `health_sciences_information_manager = 3.0`\n- `healthcare_master_person_index = 3.0`\n- `healthcare_master_person_index = 4.0`\n- `insurance_calculation_engine = 10.1.1`\n- `insurance_calculation_engine = 10.2`\n- `insurance_calculation_engine = 10.2.1`\n- `insurance_rules_palette = 10.0`\n- `insurance_rules_palette = 10.1`\n- `insurance_rules_palette = 10.2`\n- `insurance_rules_palette = 11.0`\n- `insurance_rules_palette = 11.1`\n- `primavera_gateway = 15.2`\n- `primavera_gateway = 16.2`\n- `primavera_gateway = 17.12`\n- `retail_back_office = 14.0`\n- `retail_back_office = 14.1`\n- `retail_central_office = 14.0`\n- `retail_central_office = 14.1`\n- `retail_customer_insights = 15.0`\n- `retail_customer_insights = 16.0`\n- `retail_integration_bus = 14.0.1`\n- `retail_integration_bus = 14.0.2`\n- `retail_integration_bus = 14.0.3`\n- `retail_integration_bus = 14.0.4`\n- `retail_integration_bus = 14.1.1`\n- `retail_integration_bus = 14.1.2`\n- `retail_integration_bus = 14.1.3`\n- `retail_integration_bus = 15.0.0.1`\n- `retail_integration_bus = 15.0.1`\n- `retail_integration_bus = 15.0.2`\n- `retail_integration_bus = 16.0`\n- `retail_integration_bus = 16.0.1`\n- `retail_integration_bus = 16.0.2`\n- `retail_open_commerce_platform = 5.3.0`\n- `retail_open_commerce_platform = 6.0.0`\n- `retail_open_commerce_platform = 6.0.1`\n- `retail_order_broker = 5.1`\n- `retail_order_broker = 5.2`\n- `retail_order_broker = 15.0`\n- `retail_order_broker = 16.0`\n- `retail_point-of-sale = 14.0`\n- `retail_point-of-sale = 14.1`\n- `retail_predictive_application_server = 14.0`\n- `retail_predictive_application_server = 14.1`\n- `retail_predictive_application_server = 15.0`\n- `retail_predictive_application_server = 16.0`\n- `retail_returns_management = 14.0`\n- `retail_returns_management = 14.1`\n- `retail_xstore_point_of_service = 7.1`\n- `service_architecture_leveraging_tuxedo = 12.1.3.0.0`\n- `service_architecture_leveraging_tuxedo = 12.2.2.0.0`\n- `tape_library_acsls = 8.4`\n- `fuse = 1.0.0`\n- `debian_linux = 9.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `spring_framework 5.0.5`\n- `communications_converged_application_server 7.0.0.1`\n- `communications_diameter_signaling_router 8.3`\n- `communications_performance_intelligence_center 10.2.1`\n- `communications_services_gatekeeper 6.1.0.4.0`","depth":"abyssal","depthScore":81,"depthScoreParts":{"impact":53.9,"likelihood":15.5,"exploitation":12,"ransomware":0},"changes":[]}