PT-2018-15817 · Oracle+5 · Jrockit+7

Published

2018-04-18

·

Updated

2024-06-15

·

CVE-2018-2800

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Java SE versions 6u181, 7u171, and 8u162 JRockit version R28.3.17
Description The issue allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE and JRockit. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized update, insert, or delete access to some of Java SE and JRockit accessible data, as well as unauthorized read access to a subset of Java SE and JRockit accessible data. This can be exploited by supplying data to APIs in the specified component without using untrusted Java Web Start applications or untrusted Java applets.
Recommendations For Java SE versions 6u181, 7u171, and 8u162, update to a version that contains a fix for this issue. For JRockit version R28.3.17, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the RMI component until a patch is available. Avoid using untrusted Java Web Start applications or untrusted Java applets to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CESA-2018_1188
CESA-2018_1191
CESA-2018_1270
CESA-2018_1278
CVE-2018-2800
DSA-4185-1
DSA-4225-1
MGASA-2018-0218
OPENSUSE-SU-2018_1710-1
OPENSUSE-SU-2018_1719-1
OPENSUSE-SU-2024:10876-1
RHSA-2018:1188
RHSA-2018:1191
RHSA-2018:1201
RHSA-2018:1202
RHSA-2018:1203
RHSA-2018:1204
RHSA-2018:1205
RHSA-2018:1206
RHSA-2018:1270
RHSA-2018:1278
RHSA-2018:1721
RHSA-2018:1722
RHSA-2018:1723
RHSA-2018:1724
RHSA-2018:1974
RHSA-2018:1975
RHSA-2018_1188
RHSA-2018_1191
RHSA-2018_1201
RHSA-2018_1202
RHSA-2018_1203
RHSA-2018_1204
RHSA-2018_1205
RHSA-2018_1206
RHSA-2018_1270
RHSA-2018_1278
RHSA-2018_1721
RHSA-2018_1722
RHSA-2018_1723
RHSA-2018_1724
SUSE-SU-2018:1447-1
SUSE-SU-2018:1458-1
SUSE-SU-2018:1690-1
SUSE-SU-2018:1690-2
SUSE-SU-2018:1692-1
SUSE-SU-2018:1692-2
SUSE-SU-2018:1738-1
SUSE-SU-2018:1738-2
SUSE-SU-2018:1764-1
SUSE-SU-2018:1764-2
SUSE-SU-2018:1938-1
SUSE-SU-2018:1938-2
SUSE-SU-2018:2068-1
USN-3644-1
USN-3691-1

Affected Products

Centos
Ibm Aix
Jrockit
Java Platform
Java Se
Red Hat
Suse
Ubuntu