March 25, 2022 · Applied Cybernetics Group
CVE-2018-1273 — VMware Tanzu Spring Data Commons
known ransomware use
VMware Tanzu Spring Data Commons Property Binder Vulnerability
- Added to KEV
2022-03-25- Federal due date
2022-04-15- Vendor
- VMware Tanzu
- Product
- Spring Data Commons
- EPSS
- 99.9th percentile (score 0.956, as of
2026-07-13) - NVD CVSS v3.1
- 9.8 (CRITICAL)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2018-1273
CISA short description
Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.
Required action
Apply updates per vendor instructions.
NVD description
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.