CVE-2018-1313
published 2018-05-07CVE-2018-1313: In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose location and…
PriorityP336medium5.3CVSS 3.1
AVNACHPRLUINSUCNIHAN
EPSS
4.50%
90.4th percentile
In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose location and contents are under the user's control. If the Derby Network Server is not running with a Java Security Manager policy file, the attack is successful. If the server is using a policy file, the policy file must permit the database location to be read for the attack to work. The default Derby Network Server policy file distributed with the affected releases includes a permissive policy as the default Network Server policy, which allows the attack to work.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | derby | >= 0 < 10.14.2.0-1 | 10.14.2.0-1 |
| apache | derby | >= 0 < 10.14.2.0-1 | 10.14.2.0-1 |
| apache | derby | >= 0 < 10.14.2.0-1 | 10.14.2.0-1 |
| apache | derby | >= 0 < 10.14.2.0-1 | 10.14.2.0-1 |
| apache | derby | 10.3.1.4 – 10.14.1.0 | — |
| debian | derby | < derby 10.14.2.0-1 (bookworm) | derby 10.14.2.0-1 (bookworm) |
| debian | openjdk-8 | — | — |
| netapp | e-series_santricity_os_controller | 11.0 – 11.70.1 | — |
| netapp | storage_replication_adapter_for_clustered_data_ontap | >= 9.7 | — |
| netapp | vasa_provider_for_clustered_data_ontap | >= 9.7 | — |
| netapp | virtual_storage_console | >= 9.7 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | weblogic_server | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JDK: unspecified vulnerability fixed in 6u201, 7u191, and 8u181 (Java DB)
vendor_redhat·2018-07-17·CVSS 5.3
CVE-2018-2938 [MEDIUM] JDK: unspecified vulnerability fixed in 6u201, 7u191, and 8u181 (Java DB)
JDK: unspecified vulnerability fixed in 6u201, 7u191, and 8u181 (Java DB)
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE: 6u191, 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. While the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVE-2018-2938 addresses CVE-2018-1313. CVSS 3.0 Base Scor
Red Hat
derby: Externally-controlled input vulnerability allows remote attacker to boot a database under attacker's control
vendor_redhat·2018-05-05·CVSS 5.3
CVE-2018-1313 [MEDIUM] CWE-20 derby: Externally-controlled input vulnerability allows remote attacker to boot a database under attacker's control
derby: Externally-controlled input vulnerability allows remote attacker to boot a database under attacker's control
In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose location and contents are under the user's control. If the Derby Network Server is not running with a Java Security Manager policy file, the attack is successful. If the server is using a policy file, the policy file must permit the database location to be read for the attack to work. The default Derby Network Server policy file distributed with the affected releases includes a permissive policy as the default Network Server policy, which allows the attack to work.
Package: derby (Red Hat BPM Suite 6) - Not affected
Package: pax
Debian
CVE-2018-2938: openjdk-8 - Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB)...
vendor_debian·2018·CVSS 5.3
CVE-2018-2938 [MEDIUM] CVE-2018-2938: openjdk-8 - Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB)...
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE: 6u191, 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. While the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVE-2018-2938 addresses CVE-2018-1313. CVSS 3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (
Debian
CVE-2018-1313: derby - In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be...
vendor_debian·2018·CVSS 5.3
CVE-2018-1313 [MEDIUM] CVE-2018-1313: derby - In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be...
In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose location and contents are under the user's control. If the Derby Network Server is not running with a Java Security Manager policy file, the attack is successful. If the server is using a policy file, the policy file must permit the database location to be read for the attack to work. The default Derby Network Server policy file distributed with the affected releases includes a permissive policy as the default Network Server policy, which allows the attack to work.
Scope: local
bookworm: resolved (fixed in 10.14.2.0-1)
bullseye: resolved (fixed in 10.14.2.0-1)
forky: resolved (fixed in 10.14.2.0-1)
sid: resolved (fixed in 10.14.2.0-1)
trixie: re
OSV
Improper Access Control in Apache Derby
osv·2022-05-13
CVE-2018-1313 [MEDIUM] Improper Access Control in Apache Derby
Improper Access Control in Apache Derby
In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose location and contents are under the user's control. If the Derby Network Server is not running with a Java Security Manager policy file, the attack is successful. If the server is using a policy file, the policy file must permit the database location to be read for the attack to work. The default Derby Network Server policy file distributed with the affected releases includes a permissive policy as the default Network Server policy, which allows the attack to work.
GHSA
GHSA-3vhh-58w3-43m4: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB)
ghsa_unreviewed·2022-05-13·CVSS 5.3
CVE-2018-2938 [MEDIUM] GHSA-3vhh-58w3-43m4: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB)
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE: 6u191, 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. While the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVE-2018-2938 addresses CVE-2018-1313. CVSS 3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (
GHSA
Improper Access Control in Apache Derby
ghsa·2022-05-13
CVE-2018-1313 [MEDIUM] CWE-284 Improper Access Control in Apache Derby
Improper Access Control in Apache Derby
In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose location and contents are under the user's control. If the Derby Network Server is not running with a Java Security Manager policy file, the attack is successful. If the server is using a policy file, the policy file must permit the database location to be read for the attack to work. The default Derby Network Server policy file distributed with the affected releases includes a permissive policy as the default Network Server policy, which allows the attack to work.
OSV
CVE-2018-1313: In Apache Derby 10
osv·2018-05-07·CVSS 5.3
CVE-2018-1313 [MEDIUM] CVE-2018-1313: In Apache Derby 10
In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose location and contents are under the user's control. If the Derby Network Server is not running with a Java Security Manager policy file, the attack is successful. If the server is using a policy file, the policy file must permit the database location to be read for the attack to work. The default Derby Network Server policy file distributed with the affected releases includes a permissive policy as the default Network Server policy, which allows the attack to work.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-2938 Oracle JDK: unspecified vulnerability fixed in 6u201, 7u191, and 8u181 (Java DB)
bugzilla·2018-07-17·CVSS 5.3
CVE-2018-2938 [MEDIUM] CVE-2018-2938 Oracle JDK: unspecified vulnerability fixed in 6u201, 7u191, and 8u181 (Java DB)
CVE-2018-2938 Oracle JDK: unspecified vulnerability fixed in 6u201, 7u191, and 8u181 (Java DB)
Oracle Java SE 6u201, 7u191, and 8u181 fixes an unspecified vulnerability in the Java DB component (CVE-2018-2938). Upstream has CVSS scored this issue as: 9.0/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
External Reference:
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html#AppendixJAVA
Discussion:
This issue did not affect Oracle Java SE packages as shipped via Oracle Java for Red Hat Enterprise Linux channels, as they did not include the Java DB / Apache Derby component.
---
The issue was addressed upstream by removing Java DB from the Oracle Java SE distribution. Quoting from the upstream release notes:
Removed Features and Options
other-libs/javadb
➜ Removal
Bugzilla
CVE-2018-1313 derby: Externally-controlled input vulnerability allows remote attacker to boot a database under attacker's control
bugzilla·2018-05-07·CVSS 5.3
CVE-2018-1313 [MEDIUM] CVE-2018-1313 derby: Externally-controlled input vulnerability allows remote attacker to boot a database under attacker's control
CVE-2018-1313 derby: Externally-controlled input vulnerability allows remote attacker to boot a database under attacker's control
Network Server to boot a database whose location and contents are under
the user's control. If the Derby Network Server is not running with a
Java Security Manager policy file, the attack is successful. If the
server is using a policy file, the policy file must permit the
database location to be read for the attack to work. The default
Derby Network Server policy file distributed with the affected releases
includes a permissive policy as the default Network Server policy, which
allows the attack to work.
Versions Affected: Derby 10.3.1.4 to 10.14.1.0
References:
http://openwall.com/lists/oss-security/2018/05/05/1
Discussion:
Created derby tracking bugs for
Bugzilla
CVE-2018-1313 derby: Externally-controlled input vulnerability allows remote attacker to boot a database under attacker's control [fedora-all]
bugzilla·2018-05-07·CVSS 5.3
CVE-2018-1313 [MEDIUM] CVE-2018-1313 derby: Externally-controlled input vulnerability allows remote attacker to boot a database under attacker's control [fedora-all]
CVE-2018-1313 derby: Externally-controlled input vulnerability allows remote attacker to boot a database under attacker's control [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg comm
http://www.securityfocus.com/bid/104140https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3Ehttps://lists.apache.org/thread.html/r437d94437e6aef31af689b1e7025d024d676fd1ea9901d74e3e9ae48%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r6755f48d4f5e44e39bba7dbf8d746678239d7f1f2cc108125519ce53%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/re29ab90978e6c997377fb975f674f7514f6beb642bbf79deb45477e5%40%3Cdev.hive.apache.org%3Ehttps://markmail.org/message/akkappppxcdqrgxkhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttp://www.securityfocus.com/bid/104140https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3Ehttps://lists.apache.org/thread.html/r437d94437e6aef31af689b1e7025d024d676fd1ea9901d74e3e9ae48%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r6755f48d4f5e44e39bba7dbf8d746678239d7f1f2cc108125519ce53%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/re29ab90978e6c997377fb975f674f7514f6beb642bbf79deb45477e5%40%3Cdev.hive.apache.org%3Ehttps://markmail.org/message/akkappppxcdqrgxkhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
2018-05-07
Published