CVE-2018-2633
published 2018-01-18CVE-2018-2633: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE…
PriorityP349high8.3CVSS 3.1
AVNACHPRNUIRSCCHIHAH
EPSS
5.65%
92.1th percentile
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjdk-8 | < openjdk-8 8u162-b12-1 (sid) | openjdk-8 8u162-b12-1 (sid) |
| hp | xp7_command_view | >= 8.6.2-01 | — |
| hp | xp_command_view | >= 8.6.2-01 | — |
| hp | xp_p9000_command_view | >= 8.6.2-01 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jrockit | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
CVSS provenance
nvdv3.18.3HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv8.3HIGH
vendor_debian8.3HIGH
vendor_redhat8.3HIGH
vendor_ubuntu3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v8pc-3hvj-mrwh: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI)
ghsa_unreviewed·2022-05-13
CVE-2018-2633 [HIGH] GHSA-v8pc-3hvj-mrwh: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI)
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be
OSV
openjdk-8 vulnerabilities
osv·2018-04-02·CVSS 3.7
CVE-2018-2579 [LOW] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
It was discovered that a race condition existed in the cryptography
implementation in OpenJDK. An attacker could possibly use this to expose
sensitive information. (CVE-2018-2579)
It was discovered that the Hotspot component of OpenJDK did not properly
validate uses of the invokeinterface JVM instruction. An attacker could
possibly use this to access unauthorized resources. (CVE-2018-2582)
It was discovered that the LDAP implementation in OpenJDK did not properly
encode login names. A remote attacker could possibly use this to expose
sensitive information. (CVE-2018-2588)
It was discovered that the DNS client implementation in OpenJDK did not
properly randomize source ports. A remote attacker could use this to spoof
responses to DNS queries made by Java applic
OSV
openjdk-7 vulnerabilities
osv·2018-04-02·CVSS 3.7
CVE-2018-2579 [LOW] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
It was discovered that a race condition existed in the cryptography
implementation in OpenJDK. An attacker could possibly use this to expose
sensitive information. (CVE-2018-2579)
It was discovered that the LDAP implementation in OpenJDK did not properly
encode login names. A remote attacker could possibly use this to expose
sensitive information. (CVE-2018-2588)
It was discovered that the DNS client implementation in OpenJDK did not
properly randomize source ports. A remote attacker could use this to spoof
responses to DNS queries made by Java applications. (CVE-2018-2599)
It was discovered that the Internationalization component of OpenJDK did
not restrict search paths when loading resource bundle classes. A local
attacker could use this to trick a user into
OSV
CVE-2018-2633: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI)
osv·2018-01-17·CVSS 8.3
CVE-2018-2633 [HIGH] CVE-2018-2633: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI)
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2018-04-02·CVSS 3.7
CVE-2018-2579 [LOW] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
It was discovered that a race condition existed in the cryptography
implementation in OpenJDK. An attacker could possibly use this to expose
sensitive information. (CVE-2018-2579)
It was discovered that the Hotspot component of OpenJDK did not properly
validate uses of the invokeinterface JVM instruction. An attacker could
possibly use this to access unauthorized resources. (CVE-2018-2582)
It was discovered that the LDAP implementation in OpenJDK did not properly
encode login names. A remote attacker could possibly use this to expose
sensitive information. (CVE-2018-2588)
It was discovered that the DNS client implementation in OpenJDK did not
properly randomize source ports. A remote attacker co
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2018-04-02·CVSS 3.7
CVE-2018-2579 [LOW] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
It was discovered that a race condition existed in the cryptography
implementation in OpenJDK. An attacker could possibly use this to expose
sensitive information. (CVE-2018-2579)
It was discovered that the LDAP implementation in OpenJDK did not properly
encode login names. A remote attacker could possibly use this to expose
sensitive information. (CVE-2018-2588)
It was discovered that the DNS client implementation in OpenJDK did not
properly randomize source ports. A remote attacker could use this to spoof
responses to DNS queries made by Java applications. (CVE-2018-2599)
It was discovered that the Internationalization component of OpenJDK did
not restrict search paths when loading resource bu
Red Hat
OpenJDK: LDAPCertStore insecure handling of LDAP referrals (JNDI, 8186606)
vendor_redhat·2018-01-16·CVSS 8.3
CVE-2018-2633 [HIGH] CWE-20 OpenJDK: LDAPCertStore insecure handling of LDAP referrals (JNDI, 8186606)
OpenJDK: LDAPCertStore insecure handling of LDAP referrals (JNDI, 8186606)
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded, JRockit. Note: This vulnerabilit
Debian
CVE-2018-2633: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java...
vendor_debian·2018·CVSS 8.3
CVE-2018-2633 [HIGH] CVE-2018-2633: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java...
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be
No detection rules found.
No public exploits indexed.
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.securityfocus.com/bid/102557http://www.securitytracker.com/id/1040203https://access.redhat.com/errata/RHSA-2018:0095https://access.redhat.com/errata/RHSA-2018:0099https://access.redhat.com/errata/RHSA-2018:0100https://access.redhat.com/errata/RHSA-2018:0115https://access.redhat.com/errata/RHSA-2018:0349https://access.redhat.com/errata/RHSA-2018:0351https://access.redhat.com/errata/RHSA-2018:0352https://access.redhat.com/errata/RHSA-2018:0458https://access.redhat.com/errata/RHSA-2018:0521https://access.redhat.com/errata/RHSA-2018:1463https://access.redhat.com/errata/RHSA-2018:1812https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/04/msg00003.htmlhttps://security.netapp.com/advisory/ntap-20180117-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03911en_ushttps://usn.ubuntu.com/3613-1/https://usn.ubuntu.com/3614-1/https://www.debian.org/security/2018/dsa-4144https://www.debian.org/security/2018/dsa-4166http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.securityfocus.com/bid/102557http://www.securitytracker.com/id/1040203https://access.redhat.com/errata/RHSA-2018:0095https://access.redhat.com/errata/RHSA-2018:0099https://access.redhat.com/errata/RHSA-2018:0100https://access.redhat.com/errata/RHSA-2018:0115https://access.redhat.com/errata/RHSA-2018:0349https://access.redhat.com/errata/RHSA-2018:0351https://access.redhat.com/errata/RHSA-2018:0352https://access.redhat.com/errata/RHSA-2018:0458https://access.redhat.com/errata/RHSA-2018:0521https://access.redhat.com/errata/RHSA-2018:1463https://access.redhat.com/errata/RHSA-2018:1812https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/04/msg00003.htmlhttps://security.netapp.com/advisory/ntap-20180117-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03911en_ushttps://usn.ubuntu.com/3613-1/https://usn.ubuntu.com/3614-1/https://www.debian.org/security/2018/dsa-4144https://www.debian.org/security/2018/dsa-4166
2018-01-18
Published