PT-2018-15811 · Oracle+5 · Jrockit+9

Francesco Palmarini

+3

·

Published

2018-04-18

·

Updated

2024-06-15

·

CVE-2018-2794

CVSS v3.1

7.7

High

VectorAV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Java SE versions 6u181, 7u171, 8u162, 10 JRockit version R28.3.17
Description The issue allows an unauthenticated attacker with logon to the infrastructure where Java SE, JRockit executes to compromise Java SE, JRockit. Successful attacks require human interaction from a person other than the attacker and may significantly impact additional products. The vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets, or by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.
Recommendations For Java SE versions 6u181, 7u171, 8u162, 10, update to a version that contains the fix for this issue. For JRockit version R28.3.17, update to a version that contains the fix for this issue. As a temporary workaround, consider restricting access to the Java SE, JRockit component until a patch is available. Avoid using the vulnerable Java Web Start and Java applets until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CESA-2018_1188
CESA-2018_1191
CESA-2018_1270
CESA-2018_1278
CVE-2018-2794
DSA-4185-1
DSA-4225-1
MGASA-2018-0218
OPENSUSE-SU-2018_1710-1
OPENSUSE-SU-2018_1719-1
OPENSUSE-SU-2024:10871-1
OPENSUSE-SU-2024:10872-1
OPENSUSE-SU-2024:10873-1
OPENSUSE-SU-2024:10876-1
RHSA-2018:1188
RHSA-2018:1191
RHSA-2018:1201
RHSA-2018:1202
RHSA-2018:1203
RHSA-2018:1204
RHSA-2018:1205
RHSA-2018:1206
RHSA-2018:1270
RHSA-2018:1278
RHSA-2018:1721
RHSA-2018:1722
RHSA-2018:1723
RHSA-2018:1724
RHSA-2018:1974
RHSA-2018:1975
RHSA-2018_1188
RHSA-2018_1191
RHSA-2018_1201
RHSA-2018_1202
RHSA-2018_1203
RHSA-2018_1204
RHSA-2018_1205
RHSA-2018_1206
RHSA-2018_1270
RHSA-2018_1278
RHSA-2018_1721
RHSA-2018_1722
RHSA-2018_1723
RHSA-2018_1724
SUSE-SU-2018:1447-1
SUSE-SU-2018:1458-1
SUSE-SU-2018:1690-1
SUSE-SU-2018:1690-2
SUSE-SU-2018:1692-1
SUSE-SU-2018:1692-2
SUSE-SU-2018:1738-1
SUSE-SU-2018:1738-2
SUSE-SU-2018:1764-1
SUSE-SU-2018:1764-2
SUSE-SU-2018:1938-1
SUSE-SU-2018:1938-2
SUSE-SU-2018:2068-1
USN-3644-1
USN-3691-1

Affected Products

Centos
Ibm Aix
Jrockit
Java Platform
Java Se
Java Web Start
Java Applet
Red Hat
Suse
Ubuntu