PT-2018-15933 · Oracle+5 · Jrockit+8

Daniel Bleichenbacher

·

Published

2018-07-18

·

Updated

2024-06-15

·

CVE-2018-2952

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Java SE versions 6u191, 7u181, 8u172, 10.0.1 Java SE Embedded version 8u171 JRockit version R28.3.18
Description A difficult to exploit vulnerability allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks can result in unauthorized ability to cause a partial denial of service of Java SE, Java SE Embedded, JRockit. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets, or by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets.
Recommendations For Java SE versions 6u191, 7u181, 8u172, 10.0.1, update to a version that contains a fix for this issue. For Java SE Embedded version 8u171, update to a version that contains a fix for this issue. For JRockit version R28.3.18, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the Concurrency component to minimize the risk of exploitation. Avoid using the Java Attach API in the affected component until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CESA-2018_2241
CESA-2018_2242
CESA-2018_2283
CESA-2018_2286
CVE-2018-2952
DLA-1590-1
DSA-4268-1
MGASA-2018-0366
OPENSUSE-SU-2018_2206-1
OPENSUSE-SU-2018_2247-1
OPENSUSE-SU-2018_3057-1
OPENSUSE-SU-2018_3103-1
OPENSUSE-SU-2019_0042-1
OPENSUSE-SU-2024:10871-1
OPENSUSE-SU-2024:10872-1
OPENSUSE-SU-2024:10873-1
OPENSUSE-SU-2024:10876-1
RHSA-2018:2241
RHSA-2018:2242
RHSA-2018:2253
RHSA-2018:2254
RHSA-2018:2255
RHSA-2018:2256
RHSA-2018:2283
RHSA-2018:2286
RHSA-2018:2568
RHSA-2018:2569
RHSA-2018:2575
RHSA-2018:2576
RHSA-2018:2712
RHSA-2018:2713
RHSA-2018:3007
RHSA-2018:3008
RHSA-2018_2241
RHSA-2018_2242
RHSA-2018_2253
RHSA-2018_2254
RHSA-2018_2255
RHSA-2018_2256
RHSA-2018_2283
RHSA-2018_2286
RHSA-2018_2568
RHSA-2018_2569
RHSA-2018_2575
RHSA-2018_2576
RHSA-2018_3007
RHSA-2018_3008
SUSE-SU-2018:2083-1
SUSE-SU-2018:2574-1
SUSE-SU-2018:2583-1
SUSE-SU-2018:2649-1
SUSE-SU-2018:2649-2
SUSE-SU-2018:2839-1
SUSE-SU-2018:2839-2
SUSE-SU-2018:3045-1
SUSE-SU-2018:3064-1
SUSE-SU-2018:3064-2
SUSE-SU-2018:3064-3
SUSE-SU-2018:3082-1
SUSE-SU-2019:0049-1
SUSE-SU-2019:0049-2
USN-3734-1
USN-3735-1
USN-3747-1
USN-3747-2

Affected Products

Centos
Ibm Aix
Jrockit
Java Platform
Java Se
Java Se Embedded
Red Hat
Suse
Ubuntu