PT-2018-15816 · Oracle+5 · Java Se Embedded+8

Published

2018-04-18

·

Updated

2024-06-15

·

CVE-2018-2799

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Java SE versions 7u171, 8u162, and 10 Java SE Embedded version 8u161 JRockit version R28.3.17
Description The issue allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, and JRockit. Successful attacks can result in unauthorized ability to cause a partial denial of service of Java SE, Java SE Embedded, and JRockit. This can be exploited through sandboxed Java Web Start applications, sandboxed Java applets, or by supplying data to APIs in the specified component.
Recommendations For Java SE versions 7u171, 8u162, and 10, update to a version that contains a fix for this issue. For Java SE Embedded version 8u161, update to a version that contains a fix for this issue. For JRockit version R28.3.17, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the JAXP component until a patch is available. Avoid using sandboxed Java Web Start applications and sandboxed Java applets until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CESA-2018_1188
CESA-2018_1191
CESA-2018_1270
CESA-2018_1278
CVE-2018-2799
DSA-4185-1
DSA-4225-1
MGASA-2018-0218
OESA-2023-1746
OESA-2023-1747
OESA-2023-1748
OPENSUSE-SU-2018_1710-1
OPENSUSE-SU-2018_1719-1
OPENSUSE-SU-2024:10871-1
OPENSUSE-SU-2024:10872-1
OPENSUSE-SU-2024:10873-1
OPENSUSE-SU-2024:10876-1
RHSA-2018:1188
RHSA-2018:1191
RHSA-2018:1201
RHSA-2018:1202
RHSA-2018:1204
RHSA-2018:1206
RHSA-2018:1270
RHSA-2018:1278
RHSA-2018:1721
RHSA-2018:1722
RHSA-2018:1723
RHSA-2018:1724
RHSA-2018:1974
RHSA-2018:1975
RHSA-2018_1188
RHSA-2018_1191
RHSA-2018_1201
RHSA-2018_1202
RHSA-2018_1204
RHSA-2018_1206
RHSA-2018_1270
RHSA-2018_1278
RHSA-2018_1721
RHSA-2018_1722
RHSA-2018_1723
RHSA-2018_1724
SUSE-SU-2018:1447-1
SUSE-SU-2018:1458-1
SUSE-SU-2018:1690-1
SUSE-SU-2018:1690-2
SUSE-SU-2018:1692-1
SUSE-SU-2018:1692-2
SUSE-SU-2018:1738-1
SUSE-SU-2018:1738-2
SUSE-SU-2018:1764-1
SUSE-SU-2018:1764-2
SUSE-SU-2018:1938-1
SUSE-SU-2018:1938-2
SUSE-SU-2018:2068-1
USN-3644-1
USN-3691-1

Affected Products

Centos
Ibm Aix
Jrockit
Java Platform
Java Se
Java Se Embedded
Red Hat
Suse
Ubuntu