CVE Vulnerabilities

CVE-2018-2657

Published: Jan 18, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u171 and 7u161; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, JRockit. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

Affected Software

NameVendorStart VersionEnd Version
JdkOracle1.6.0-update171 (including)1.6.0-update171 (including)
JdkOracle1.7.0-update161 (including)1.7.0-update161 (including)
JreOracle1.6.0-update171 (including)1.6.0-update171 (including)
JreOracle1.7.0-update161 (including)1.7.0-update161 (including)
JrockitOracler28.3.16 (including)r28.3.16 (including)
Oracle Java for Red Hat Enterprise Linux 6RedHatjava-1.7.0-oracle-1:1.7.0.171-1jpp.1.el6_9*
Oracle Java for Red Hat Enterprise Linux 6RedHatjava-1.6.0-sun-1:1.6.0.181-1jpp.1.el6*
Oracle Java for Red Hat Enterprise Linux 7RedHatjava-1.7.0-oracle-1:1.7.0.171-1jpp.1.el7*
Oracle Java for Red Hat Enterprise Linux 7RedHatjava-1.6.0-sun-1:1.6.0.181-1jpp.2.el7*
Red Hat Enterprise Linux 6 SupplementaryRedHatjava-1.7.1-ibm-1:1.7.1.4.20-1jpp.3.el6_9*
Red Hat Enterprise Linux 7 SupplementaryRedHatjava-1.7.1-ibm-1:1.7.1.4.20-1jpp.1.el7*
Red Hat Satellite 5.6RedHatjava-1.7.1-ibm-1:1.7.1.4.20-1jpp.3.el6_9*
Red Hat Satellite 5.7RedHatjava-1.7.1-ibm-1:1.7.1.4.20-1jpp.3.el6_9*
Red Hat Satellite 5.8RedHatjava-1.8.0-ibm-1:1.8.0.5.10-1jpp.1.el6_9*

References