CVE-2018-1273
CVE-2018-1273 is a critical-severity vulnerability in Broadcom Spring Data Commons with a CVSS 3.x base score of 9.8. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2022-03-25). The underlying weakness is classified as CWE-94.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v2: 7.5
- EPSS exploit prediction: 96% (100th percentile)
- Actively exploited: Yes — listed in CISA KEV (added 2022-03-25)
- EU (EUVD) id: EUVD-2018-0500
- EU exploitation: Flagged exploited in the ENISA EU Vulnerability Database (since 2022-03-25)
- Weakness: CWE-94
- Affected product: Broadcom Spring Data Commons
- Published:
- Last modified:
Description
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
Frequently asked questions
- What is CVE-2018-1273?
- Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
- How severe is CVE-2018-1273?
- CVE-2018-1273 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2018-1273 being actively exploited?
- Yes. CVE-2018-1273 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2022-03-25, which means active exploitation has been confirmed. It should be prioritised for remediation.
- What products are affected by CVE-2018-1273?
- CVE-2018-1273 primarily affects Broadcom Spring Data Commons. In total, 8 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2018-1273?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
- Does CVE-2018-1273 have an EU (EUVD) identifier?
- Yes. CVE-2018-1273 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2018-0500. It is also flagged as exploited in the EUVD (since 2022-03-25).
- When was CVE-2018-1273 published?
- CVE-2018-1273 was published on 2018-04-11 and last updated on 2026-06-26.
References
- http://mail-archives.apache.org/mod_mbox/ignite-dev/201807.mbox/%3CCAK0qHnqzfzmCDFFi6c5Jok19zNkVCz5Xb4sU%3D0f2J_1i4p46zQ%40mail.gmail.com%3E
- https://pivotal.io/security/cve-2018-1273
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-1273
Affected products (8)
- cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:*
- cpe:2.3:a:pivotal_software:spring_data_rest:*:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:spring_data_rest:*:*:*:*:*:*:*:*
- cpe:2.3:a:apache:ignite:*:*:*:*:*:*:*:*
- cpe:2.3:a:apache:ignite:1.0.0:-:*:*:*:*:*:*
- cpe:2.3:a:apache:ignite:1.0.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.3.0:*:*:*:*:*:*:*
More vulnerabilities in Broadcom Spring Data Commons
- CVE-2026-41716 — High (CVSS 7.5): Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys,…
- CVE-2026-41695 — High (CVSS 7.5): Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when…
- CVE-2018-1259 — High (CVSS 7.5): Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or…
- CVE-2018-1274 — High (CVSS 7.5): Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path…
- CVE-2026-41721 — Medium (CVSS 5.9): Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web…
- CVE-2026-41711 — Medium (CVSS 5.9): Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a…
All CVEs affecting Broadcom Spring Data Commons →
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-76605 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-76604 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The…
- CVE-2026-67364 — Critical (CVSS 10.0): Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1:…
- CVE-2026-73343 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
- CVE-2026-74253 — Critical (CVSS 10.0): Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0…
- CVE-2026-73678 — Critical (CVSS 10.0): MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that…