Apply updates per vendor instructions.
Evidence dossier
CVE-2018-1273
CVE-2018-1273
gen-409cbd0cNormalized restatement
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
- State
- PUBLISHED
- Published
- Apr 11, 2018
- Updated
- Oct 21, 2025
- Evidence coverage
- 72%
2026-07-18 · v2026.06.15 · percentile 99.9%
Distinct CVSS assessments remain side by side; none are averaged.
Source comparison
Who said what
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
VMware Tanzu Spring Data Commons Property Binder Vulnerability
Probability 0.956490000000; percentile 0.998620000000
Applicability
Cited product scope
Grouped from 4 configuration nodes in this exact generation. Visual grouping does not establish asset exposure or common root cause.
Identity source boundaries
- cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
6 scope groups
[{"status": "affected", "version": "Versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions"}]Any version (unconstrained) (>= 1.0.1, <= 2.5.0); Version 1.0.0Canonical identity product-25a46cb60c6b5042c22d84feb7094fff8eadd27c4c977037364e96dd6d256752linked exactInspect 3 returned assertions
cpe:2.3:a:apache:ignite:1.0.0:rc3:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
be7dccd6-7d9e-47ea-8b6e-3b83b5b06e68
cpe:2.3:a:apache:ignite:1.0.0:-:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f78dc740-7a30-4f38-9289-9e0c8ef14d0f
cpe:2.3:a:apache:ignite:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 1.0.1; through including 2.5.0
- Match ID
f234d76f-9eea-4bf9-a8c6-56624d0bcf96
Any version (unconstrained) (<= 1.12.10); Any version (unconstrained) (>= 1.13.0, <= 1.13.10); Any version (unconstrained) (>= 2.0.0, <= 2.0.5)Canonical identity product-fce09c30845a1e1c9439ae9887af586df83f3ef7d00af7c4c3c47c0506fd39f8linked exactInspect 3 returned assertions
cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 2.0.0; through including 2.0.5
- Match ID
a0baa03c-73c8-48cd-b566-16e1a3f77661
cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 1.13.0; through including 1.13.10
- Match ID
66999642-5cba-4037-9572-63897ed925b3
cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 1.12.10
- Match ID
796986c2-3ae7-480f-b8de-242dcdb9fd29
Version 8.0.8.2.0; Version 8.0.8.3.0Canonical identity product-2762b30e1de8fdfbb97b83873b584f00a5f913817e42c9c8cabc6721ba50c6aalinked exactInspect 2 returned assertions
cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.2.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
55f091c7-0869-4fd6-ac73-da697d990304
cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.3.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4d134c60-f9e2-46c2-8466-db90ad98439e
Any version (unconstrained) (>= 3.0.0, <= 3.0.5)Canonical identity product-c2f64f1121b077f105ca164cffa22493aecec6a9f337d7e33ae0e1fddec79bcblinked exactInspect 1 returned assertions
cpe:2.3:a:pivotal_software:spring_data_rest:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 3.0.0; through including 3.0.5
- Match ID
982582fd-1bc2-4431-8aae-2771a5904fcc
Any version (unconstrained) (<= 2.5.10); Any version (unconstrained) (>= 2.6.0, <= 2.6.10)Canonical identity product-f07ebd61ab0295eb58cc26bc2980cbc4088110fb91e61c9bc222b97c0ebf5390linked exactInspect 2 returned assertions
cpe:2.3:a:vmware:spring_data_rest:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- through including 2.5.10
- Match ID
b10ce829-5cc9-4607-9a3b-f54596d8736b
cpe:2.3:a:vmware:spring_data_rest:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 2.6.0; through including 2.6.10
- Match ID
3357249e-1a8f-43f9-a9ae-3bd8e114c70f
Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:P/I:P/A:PCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLimitations and unknowns
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D remains unknown because WC-03 has not converted canonical CPE mappings into generation-bound mapping obligations; canonical identity alone does not score applicability.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.