PT-2018-12919 · Ibm+3 · Ibm Sdk+4

Publicado

2018-08-20

·

Atualizado

2019-10-09

·

CVE-2018-1517

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM SDK, Java Technology Edition versions 6.0 through 8.0 Eclipse OpenJ9 (affected versions not specified)
Description A flaw in the java.math component may allow an attacker to inflict a denial-of-service attack with specially crafted String data. Additionally, Eclipse OpenJ9 could allow a local attacker to gain elevated privileges on the system due to the failure to restrict the use of Java Attach API. This could enable an attacker to execute untrusted native code and gain elevated privileges on the system.
Recommendations For IBM SDK, Java Technology Edition versions 6.0 through 8.0, update to a version that includes the fix for the java.math component flaw. For Eclipse OpenJ9, restrict the use of Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and limit Attach API operations to only the process owner. As a temporary workaround, consider disabling the Java Attach API until a patch is available.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1517
RHSA-2018:2568
RHSA-2018:2569
RHSA-2018:2575
RHSA-2018:2576
RHSA-2018:2712
RHSA-2018:2713
RHSA-2018_2568
RHSA-2018_2569
RHSA-2018_2575
RHSA-2018_2576
SUSE-SU-2018:2574-1
SUSE-SU-2018:2583-1
SUSE-SU-2018:2649-1
SUSE-SU-2018:2649-2
SUSE-SU-2018:2839-1
SUSE-SU-2018:2839-2
SUSE-SU-2018:3082-1

Produtos afetados

Eclipse Openj9
Ibm Aix
Ibm Sdk
Red Hat
Suse