Broadcom
Broadcom Spring Data Commons: vulnerabilidades y CVE
Broadcom Spring Data Commons tiene 7 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses4
Críticas1
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-1273 | Crítica (9.8) | 97% | ⚠ Explotación activa | 11 abr 2018 | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-41721 | Media (5.9) | 0.44% | — | 10 jun 2026 | Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunction with a Controller method using @ProjectedPayload, when an attacker… |
| CVE-2026-41716 | Alta (7.5) | 0.46% | — | 10 jun 2026 | Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion through repeated requests. Affected versions: Spring Data Commons 2.7.0… |
| CVE-2026-41711 | Media (5.9) | 0.37% | — | 10 jun 2026 | Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when parsing Sort parameters. Affected versions: Spring Data Commons 4.0.0 through 4.0.5;… |
| CVE-2026-41695 | Alta (7.5) | 0.46% | — | 10 jun 2026 | Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings are passed to MappingContext property path resolution. Affected… |
| CVE-2018-1259 | Alta (7.5) | 4.9% | — | 11 may 2018 | Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML… |
| CVE-2018-1274 | Alta (7.5) | 1.9% | — | 18 abr 2018 | Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user… |
| CVE-2018-1273 | Crítica (9.8) | 97% | ⚠ Explotación activa | 11 abr 2018 | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Broadcom
Fabric Operating System · 95Brocade Sannav · 54Tcpreplay · 52Brightstor Arcserve Backup · 41Brocade Fabric Operating System Firmware · 26Rabbitmq Server · 25Raid Controller WEB Interface · 22Sannav · 20Brightstor Enterprise Backup · 19Advanced Secure Gateway · 16Business Protection Suite · 16Etrust Antivirus · 16