CVE: CVE-2012-1833

Export to Word

VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass intended access restrictions and modify arbitrary object properties via a crafted request parameter to an application.

Threat-Mapped Scoring

Score: 1.8

Priority: P4 - Informational (Low)

EPSS

Score: 0.00255
Percentile: 0.48749

CVSS Scoring

CVSS v2 Score: 5.0

Severity:

Affected Products

← Back to Home