CVE-2018-1258: Netapp Oncommand Insight

High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.

Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.

Affected products

  • Netapp Oncommand Insight: affected versions not specified
  • Netapp Oncommand Unified Manager: from 7.3; from 9.4
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Snapcenter: affected versions not specified
  • Netapp Storage Automation Store: affected versions not specified
  • Oracle Agile Product Lifecycle Management: version 9.3.3 only; version 9.3.4 only; version 9.3.5 only; version 9.3.6 only
  • Oracle Application Testing Suite: version 10.1 only; version 12.5.0.3 only; version 13.1.0.1 only; version 13.2.0.1 only; version 13.3.0.1 only
  • Oracle Big Data Discovery: version 1.6.0 only
  • Oracle Communications Converged Application Server: before 7.0.0.1 (fixed in 7.0.0.1)
  • Oracle Communications Diameter Signaling Router: before 8.3 (fixed in 8.3)
  • Oracle Communications Network Integrity: from 7.3.2, up to and including 7.3.6
  • Oracle Communications Performance Intelligence Center: before 10.2.1 (fixed in 10.2.1)
  • Oracle Communications Services Gatekeeper: before 6.1.0.4.0 (fixed in 6.1.0.4.0)
  • Oracle Endeca Information Discovery Integrator: version 3.1.0 only; version 3.2.0 only
  • Oracle Enterprise Manager For MySQL Database: version 13.2 only
  • Oracle Enterprise Manager Ops Center: version 12.2.2 only; version 12.3.3 only
  • Oracle Enterprise Repository: version 11.1.1.7.0 only; version 12.1.3.0.0 only
  • Oracle Goldengate For Big Data: version 12.2.0.1 only; version 12.3.1.1 only; version 12.3.2.1 only
  • Oracle Health Sciences Information Manager: version 3.0 only
  • Oracle Healthcare Master Person Index: version 3.0 only; version 4.0 only
  • Oracle Hospitality Guest Access: version 4.2.0 only; version 4.2.1 only
  • Oracle Insurance Calculation Engine: version 10.1.1 only; version 10.2 only; version 10.2.1 only
  • Oracle Insurance Policy Administration: version 10.0 only; version 10.1 only; version 10.2 only; version 11.0 only
  • Oracle Insurance Rules Palette: version 10.0 only; version 10.1 only; version 10.2 only; version 11.0 only; version 11.1 only
  • Oracle Micros Lucas: version 2.9.5 only
  • and 17 more

Published 2018-05-11. Last modified 2026-08-25.