CVE-2018-1517Improper Input Validation in IBM Software Development KIT

Severity
7.5HIGHNVD
CNA5.9
EPSS
0.6%
top 30.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 20
Latest updateMay 13

Description

A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data. IBM X-Force ID: 141681.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

🔴Vulnerability Details

2
GHSA
GHSA-m9w3-gv68-h6xv: A flaw in the java2022-05-13
CVEList
CVE-2018-1517: A flaw in the java2018-08-20

📋Vendor Advisories

1
Red Hat
JDK: DoS in the java.math component2018-08-16

💬Community

1
Bugzilla
CVE-2018-1517 IBM JDK: DoS in the java.math component2018-08-17
CVE-2018-1517 — Improper Input Validation in IBM | cvebase