CVE-2018-11039: Debian Linux

Medium severity, CVSS 5.9. EPSS: 2.7% chance of exploitation in the next 30 days.

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Oracle Agile Product Lifecycle Management: version 9.3.3 only; version 9.3.4 only; version 9.3.5 only; version 9.3.6 only
  • Oracle Application Testing Suite: version 12.5.0.3 only; version 13.1.0.1 only; version 13.2.0.1 only; version 13.3.0.1 only
  • Oracle Communications Diameter Signaling Router: before 8.3 (fixed in 8.3)
  • Oracle Communications Network Integrity: from 7.3.2, up to and including 7.3.6
  • Oracle Communications Online Mediation Controller: version 6.1 only
  • Oracle Communications Performance Intelligence Center: before 10.2.1 (fixed in 10.2.1)
  • Oracle Communications Services Gatekeeper: before 6.1.0.4.0 (fixed in 6.1.0.4.0)
  • Oracle Communications Unified Inventory Management: version 7.3.2 only; version 7.3.4 only; version 7.3.5 only; version 7.4.0 only
  • Oracle Endeca Information Discovery Integrator: version 3.1.0 only; version 3.2.0 only
  • Oracle Enterprise Manager Base Platform: version 12.1.0.5.0 only; version 13.2.0.0.0 only; version 13.3.0.0.0 only
  • Oracle Enterprise Manager For MySQL Database: version 13.2 only
  • Oracle Enterprise Manager Ops Center: version 12.3.3 only
  • Oracle Health Sciences Information Manager: version 3.0 only
  • Oracle Healthcare Master Person Index: version 3.0 only; version 4.0 only
  • Oracle Hospitality Guest Access: version 4.2.0 only; version 4.2.1 only
  • Oracle Insurance Calculation Engine: from 11.0.0, up to and including 11.3.1; version 10.2 only
  • Oracle Insurance Rules Palette: version 10.0 only; version 10.2 only
  • Oracle Micros Lucas: version 2.9.5 only
  • Oracle MySQL Enterprise Monitor: up to and including 3.4.9.4237; from 4.0.0, up to and including 4.0.6.5281; from 8.0.0, up to and including 8.0.2.8191
  • Oracle Primavera p6 Enterprise Project Portfolio Management: version 18.8 only
  • Oracle Retail Advanced Inventory Planning: version 15.0 only
  • Oracle Retail Assortment Planning: version 14.1 only; version 15.0 only; version 16.0 only
  • Oracle Retail Clearance Optimization Engine: version 14.0.5 only
  • Oracle Retail Customer Insights: version 15.0 only; version 16.0 only
  • and 8 more

Published 2018-06-25. Last modified 2026-10-08.