Severity
5.3MEDIUM
EPSS
0.8%
top 26.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 7
Latest updateMay 13

Description

In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose location and contents are under the user's control. If the Derby Network Server is not running with a Java Security Manager policy file, the attack is successful. If the server is using a policy file, the policy file must permit the database location to be read for the attack to work. The default Derby Network Server policy file distributed with the a

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages6 packages

Mavenorg.apache.derby:derby10.3.1.410.14.2.0
NVDapache/derby10.3.1.410.14.1.0
CVEListV5apache_software_foundation/apache_derby10.3.1.4 to 10.14.1.0
Debianderby< 10.14.2.0-1+3

Patches

🔴Vulnerability Details

4
OSV
Improper Access Control in Apache Derby2022-05-13
GHSA
Improper Access Control in Apache Derby2022-05-13
CVEList
CVE-2018-1313: In Apache Derby 102018-05-07
OSV
CVE-2018-1313: In Apache Derby 102018-05-07

📋Vendor Advisories

3
Red Hat
JDK: unspecified vulnerability fixed in 6u201, 7u191, and 8u181 (Java DB)2018-07-17
Red Hat
derby: Externally-controlled input vulnerability allows remote attacker to boot a database under attacker's control2018-05-05
Debian
CVE-2018-1313: derby - In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be...2018

💬Community

2
Bugzilla
CVE-2018-1313 derby: Externally-controlled input vulnerability allows remote attacker to boot a database under attacker's control2018-05-07
Bugzilla
CVE-2018-1313 derby: Externally-controlled input vulnerability allows remote attacker to boot a database under attacker's control [fedora-all]2018-05-07
CVE-2018-1313 (MEDIUM CVSS 5.3) | In Apache Derby 10.3.1.4 to 10.14.1 | cvebase.io