PT-2012-3578 · Vmware · Vmware Springsource Grails

Published

2012-09-28

·

Updated

2013-03-02

·

CVE-2012-1833

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions VMware SpringSource Grails versions prior to 1.3.8 VMware SpringSource Grails versions 2.x prior to 2.0.2
Description The issue is related to improper restriction of data binding, which could allow remote attackers to bypass intended access restrictions and modify arbitrary object properties via a crafted request parameter to an application.
Recommendations For versions prior to 1.3.8, update to version 1.3.8 or later. For versions 2.x prior to 2.0.2, update to version 2.0.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1833

Affected Products

Vmware Springsource Grails