cvedb.io
CVE-2017-8046
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2018-01-04T06:29:00.307 · Last modified 2026-06-26T18:44:14.703

Summary

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.

Affected products

vmware — spring_boot

Does this affect you?

Add your gear to cvedb and we'll alert you only when vmware ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.