CVE-2018-1273: VMware Tanzu Spring Data Commons Property Binder Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 97% chance of exploitation in the next 30 days.

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

Affected products

  • Apache Ignite: from 1.0.1, up to and including 2.5.0; version 1.0.0 only
  • Broadcom Spring Data Commons: up to and including 1.12.10; from 1.13.0, up to and including 1.13.10; from 2.0.0, up to and including 2.0.5
  • Oracle Financial Services Crime And Compliance Management Studio: version 8.0.8.2.0 only; version 8.0.8.3.0 only
  • Pivotal Software Spring Data Rest: from 3.0.0, up to and including 3.0.5
  • VMware Spring Data Rest: up to and including 2.5.10; from 2.6.0, up to and including 2.6.10

Published 2018-04-11. Last modified 2026-08-26.