CVE-2018-2588
published 2018-01-18CVE-2018-2588: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that are affected are Java SE…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
3.44%
87.6th percentile
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjdk-8 | < openjdk-8 8u162-b12-1 (sid) | openjdk-8 8u162-b12-1 (sid) |
| hp | xp7_command_view | >= 8.6.2-01 | — |
| hp | xp_command_view | >= 8.6.2-01 | — |
| hp | xp_p9000_command_view | >= 8.6.2-01 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jrockit | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2018-04-02·CVSS 3.7
CVE-2018-2579 [LOW] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
It was discovered that a race condition existed in the cryptography
implementation in OpenJDK. An attacker could possibly use this to expose
sensitive information. (CVE-2018-2579)
It was discovered that the Hotspot component of OpenJDK did not properly
validate uses of the invokeinterface JVM instruction. An attacker could
possibly use this to access unauthorized resources. (CVE-2018-2582)
It was discovered that the LDAP implementation in OpenJDK did not properly
encode login names. A remote attacker could possibly use this to expose
sensitive information. (CVE-2018-2588)
It was discovered that the DNS client implementation in OpenJDK did not
properly randomize source ports. A remote attacker co
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2018-04-02·CVSS 3.7
CVE-2018-2579 [LOW] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
It was discovered that a race condition existed in the cryptography
implementation in OpenJDK. An attacker could possibly use this to expose
sensitive information. (CVE-2018-2579)
It was discovered that the LDAP implementation in OpenJDK did not properly
encode login names. A remote attacker could possibly use this to expose
sensitive information. (CVE-2018-2588)
It was discovered that the DNS client implementation in OpenJDK did not
properly randomize source ports. A remote attacker could use this to spoof
responses to DNS queries made by Java applications. (CVE-2018-2599)
It was discovered that the Internationalization component of OpenJDK did
not restrict search paths when loading resource bu
Red Hat
OpenJDK: LdapLoginModule insufficient username encoding in LDAP query (LDAP, 8178449)
vendor_redhat·2018-01-16·CVSS 4.3
CVE-2018-2588 [MEDIUM] CWE-90 OpenJDK: LdapLoginModule insufficient username encoding in LDAP query (LDAP, 8178449)
OpenJDK: LdapLoginModule insufficient username encoding in LDAP query (LDAP, 8178449)
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java app
Debian
CVE-2018-2588: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java...
vendor_debian·2018·CVSS 4.3
CVE-2018-2588 [MEDIUM] CVE-2018-2588: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java...
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component wit
GHSA
GHSA-gmfr-4fv6-88fh: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP)
ghsa_unreviewed·2022-05-13
CVE-2018-2588 [MEDIUM] GHSA-gmfr-4fv6-88fh: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP)
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component wit
OSV
openjdk-8 vulnerabilities
osv·2018-04-02·CVSS 3.7
CVE-2018-2579 [LOW] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
It was discovered that a race condition existed in the cryptography
implementation in OpenJDK. An attacker could possibly use this to expose
sensitive information. (CVE-2018-2579)
It was discovered that the Hotspot component of OpenJDK did not properly
validate uses of the invokeinterface JVM instruction. An attacker could
possibly use this to access unauthorized resources. (CVE-2018-2582)
It was discovered that the LDAP implementation in OpenJDK did not properly
encode login names. A remote attacker could possibly use this to expose
sensitive information. (CVE-2018-2588)
It was discovered that the DNS client implementation in OpenJDK did not
properly randomize source ports. A remote attacker could use this to spoof
responses to DNS queries made by Java applic
OSV
openjdk-7 vulnerabilities
osv·2018-04-02·CVSS 3.7
CVE-2018-2579 [LOW] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
It was discovered that a race condition existed in the cryptography
implementation in OpenJDK. An attacker could possibly use this to expose
sensitive information. (CVE-2018-2579)
It was discovered that the LDAP implementation in OpenJDK did not properly
encode login names. A remote attacker could possibly use this to expose
sensitive information. (CVE-2018-2588)
It was discovered that the DNS client implementation in OpenJDK did not
properly randomize source ports. A remote attacker could use this to spoof
responses to DNS queries made by Java applications. (CVE-2018-2599)
It was discovered that the Internationalization component of OpenJDK did
not restrict search paths when loading resource bundle classes. A local
attacker could use this to trick a user into
OSV
CVE-2018-2588: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP)
osv·2018-01-17·CVSS 4.3
CVE-2018-2588 [MEDIUM] CVE-2018-2588: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP)
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component wit
No detection rules found.
No public exploits indexed.
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.securityfocus.com/bid/102661http://www.securitytracker.com/id/1040203https://access.redhat.com/errata/RHSA-2018:0095https://access.redhat.com/errata/RHSA-2018:0099https://access.redhat.com/errata/RHSA-2018:0100https://access.redhat.com/errata/RHSA-2018:0115https://access.redhat.com/errata/RHSA-2018:0349https://access.redhat.com/errata/RHSA-2018:0351https://access.redhat.com/errata/RHSA-2018:0352https://access.redhat.com/errata/RHSA-2018:0458https://access.redhat.com/errata/RHSA-2018:0521https://access.redhat.com/errata/RHSA-2018:1463https://access.redhat.com/errata/RHSA-2018:1812https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/04/msg00003.htmlhttps://security.netapp.com/advisory/ntap-20180117-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03911en_ushttps://usn.ubuntu.com/3613-1/https://usn.ubuntu.com/3614-1/https://www.debian.org/security/2018/dsa-4144https://www.debian.org/security/2018/dsa-4166http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.securityfocus.com/bid/102661http://www.securitytracker.com/id/1040203https://access.redhat.com/errata/RHSA-2018:0095https://access.redhat.com/errata/RHSA-2018:0099https://access.redhat.com/errata/RHSA-2018:0100https://access.redhat.com/errata/RHSA-2018:0115https://access.redhat.com/errata/RHSA-2018:0349https://access.redhat.com/errata/RHSA-2018:0351https://access.redhat.com/errata/RHSA-2018:0352https://access.redhat.com/errata/RHSA-2018:0458https://access.redhat.com/errata/RHSA-2018:0521https://access.redhat.com/errata/RHSA-2018:1463https://access.redhat.com/errata/RHSA-2018:1812https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/04/msg00003.htmlhttps://security.netapp.com/advisory/ntap-20180117-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03911en_ushttps://usn.ubuntu.com/3613-1/https://usn.ubuntu.com/3614-1/https://www.debian.org/security/2018/dsa-4144https://www.debian.org/security/2018/dsa-4166
2018-01-18
Published