Applied Cybernetics Group
Threat intel → detection pipeline
Tuesday, July 14, 2026
Data as of 20:11 UTC

known ransomware use

VMware Tanzu Spring Data Commons Property Binder Vulnerability

Added to KEV
2022-03-25
Federal due date
2022-04-15
Vendor
VMware Tanzu
Product
Spring Data Commons
EPSS
99.9th percentile (score 0.956, as of 2026-07-13)
NVD CVSS v3.1
9.8 (CRITICAL)
Ransomware use
Known
Upstream
https://nvd.nist.gov/vuln/detail/CVE-2018-1273

CISA short description

Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.

Required action

Apply updates per vendor instructions.

NVD description

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

EPSS percentile is the FIRST.org exploit-probability ranking as of the date noted above; it moves daily. CVSS reflects NVD's analysis at time of publication.