← Back

CVE-2018-2627

nvd nist
Published: Jan 18, 2018Modified: May 6, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 6.0
Source: NVD

Description

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Installer). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to the Windows installer only. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).

Affected (27)

2 products
Jdk
Jre
1 product
Satellite
17 products
Active Iq Unified Manager
Cloud Backup
E Series Santricity Os Controller
E Series Santricity Web Services
Oncommand Insight
Oncommand Shift
Oncommand Unified Manager
Oncommand Workflow Automation
Plug In For Symantec Netbackup
Santricity Cloud Connector
Snapmanager
Storagegrid
Virtual Storage Console
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 1.8.0 update152
Version 9.0.1
Oracle
Version 1.8.0 update152
Version 9.0.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.8
Configuration C
22 vulnerable

References (14)

Source: secalert_us@oracle.com
PatchVendor Advisory
Source: secalert_us@oracle.com
Broken LinkThird Party AdvisoryVDB Entry
Source: secalert_us@oracle.com
Broken LinkThird Party AdvisoryVDB Entry
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.