← Back

CVE-2018-2657

nvd nist
Published: Jan 18, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u171 and 7u161; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, JRockit. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

Affected (17)

Show all products
3 products
Jdk
Jre
Jrockit
5 products
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Server Eus
Enterprise Linux Workstation
Satellite
Struxureware Data Center Expert
3 products
Xp7 Command View
Xp Command View
Xp P9000 Command View
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 1.6.0 update171
Version 1.7.0 update161
Oracle
Version 1.6.0 update171
Version 1.7.0 update161
Version r28.3.16
Configuration B
8 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.0
Redhat
Version 6.0
Version 7.0
Version 7.5
Version 6.0
Redhat
Version 5.6
Version 5.7
Version 5.8
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 7.6.0
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
From 8.6.2-01
From 8.6.2-01
From 8.6.2-01

References (24)

Source: secalert_us@oracle.com
Third Party AdvisoryVDB Entry
Source: secalert_us@oracle.com
Third Party AdvisoryVDB Entry
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.