EXPOSURES › CVE-2018-1273
CVE-2018-1273
CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 95/100
ransomwarerceexploited-in-wild
VMware Tanzu Spring Data Commons contained a remote code execution vulnerability actively exploited in ransomware attacks, impacting DIB organizations using this software stack.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.
AFFECTED FEDRAMP PRODUCTS · 16
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Clarity Broadcom |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| General Support Systems (GSS) Broadcom |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Rally Broadcom |
Authorized |
| Symantec Gov Cloud Security (GCS) Broadcom |
In Process |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |