Skip to content
COOEY

FAIL › dossier

Spring Data Commons

PRODUCT

· dossier confidence 20%

Spring Data Commons is a widely adopted Java framework for data access that suffered a critical RCE vulnerability (CVE-2018-1273) actively exploited in ransomware attacks, posing significant risk to DIB organizations relying on it.

PROFILE
CategorysoftwareWhat they doSpring Data Commons is a Java-based framework providing a consistent programming model for data access and persistence across different data stores. Websitehttps://spring.io/projects/spring-data ↗
SECURITY POSTURE

The company has a critical vulnerability history, with CVE-2018-1273 being actively exploited in ransomware attacks against DIB organizations using Spring Data Commons.

Notable failures
  • CVE-2018-1273 RCE actively exploited in ransomware
  • CVE-2018-1273 critical RCE in Spring Data Commons
Patterns: critical RCE vulnerabilities in widely used Java frameworks
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2018-1273 critical VMware Tanzu Spring Data Commons contained a remote code execution vulnerability actively exploited in ransomware attacks, impacting DIB organizations using this software stack.
2018-04-11 CVE-2018-1273 critical CVE-2018-1273: Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older
Open questions: What is the exact founding date of Spring Data Commons? · What is the exact headquarters location of the Spring project? · What is the exact size of the Spring Data Commons team?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-27 04:03:21.641445+00:00