PT-2018-12919 · Ibm+3 · Ibm Sdk+4

Published

2018-08-20

·

Updated

2019-10-09

·

CVE-2018-1517

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM SDK, Java Technology Edition versions 6.0 through 8.0 Eclipse OpenJ9 (affected versions not specified)
Description A flaw in the java.math component may allow an attacker to inflict a denial-of-service attack with specially crafted String data. Additionally, Eclipse OpenJ9 could allow a local attacker to gain elevated privileges on the system due to the failure to restrict the use of Java Attach API. This could enable an attacker to execute untrusted native code and gain elevated privileges on the system.
Recommendations For IBM SDK, Java Technology Edition versions 6.0 through 8.0, update to a version that includes the fix for the java.math component flaw. For Eclipse OpenJ9, restrict the use of Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and limit Attach API operations to only the process owner. As a temporary workaround, consider disabling the Java Attach API until a patch is available.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1517
RHSA-2018:2568
RHSA-2018:2569
RHSA-2018:2575
RHSA-2018:2576
RHSA-2018:2712
RHSA-2018:2713
RHSA-2018_2568
RHSA-2018_2569
RHSA-2018_2575
RHSA-2018_2576
SUSE-SU-2018:2574-1
SUSE-SU-2018:2583-1
SUSE-SU-2018:2649-1
SUSE-SU-2018:2649-2
SUSE-SU-2018:2839-1
SUSE-SU-2018:2839-2
SUSE-SU-2018:3082-1

Affected Products

Eclipse Openj9
Ibm Aix
Ibm Sdk
Red Hat
Suse