CVE-2018-2634
published 2018-01-18CVE-2018-2634: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 7u161, 8u152…
PriorityP338medium6.8CVSS 3.1
AVNACHPRNUINSCCHINAN
EPSS
4.53%
90.5th percentile
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tika | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjdk-8 | < openjdk-8 8u162-b12-1 (sid) | openjdk-8 8u162-b12-1 (sid) |
| hp | xp7_command_view | >= 8.6.2-01 | — |
| hp | xp_command_view | >= 8.6.2-01 | — |
| hp | xp_p9000_command_view | >= 8.6.2-01 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.8MEDIUM
vendor_apache9.8CRITICAL
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qffx-cq52-9cp7: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS)
ghsa_unreviewed·2022-05-13
CVE-2018-2634 [MEDIUM] GHSA-qffx-cq52-9cp7: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code
OSV
openjdk-8 vulnerabilities
osv·2018-04-02·CVSS 3.7
CVE-2018-2579 [LOW] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
It was discovered that a race condition existed in the cryptography
implementation in OpenJDK. An attacker could possibly use this to expose
sensitive information. (CVE-2018-2579)
It was discovered that the Hotspot component of OpenJDK did not properly
validate uses of the invokeinterface JVM instruction. An attacker could
possibly use this to access unauthorized resources. (CVE-2018-2582)
It was discovered that the LDAP implementation in OpenJDK did not properly
encode login names. A remote attacker could possibly use this to expose
sensitive information. (CVE-2018-2588)
It was discovered that the DNS client implementation in OpenJDK did not
properly randomize source ports. A remote attacker could use this to spoof
responses to DNS queries made by Java applic
OSV
openjdk-7 vulnerabilities
osv·2018-04-02·CVSS 3.7
CVE-2018-2579 [LOW] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
It was discovered that a race condition existed in the cryptography
implementation in OpenJDK. An attacker could possibly use this to expose
sensitive information. (CVE-2018-2579)
It was discovered that the LDAP implementation in OpenJDK did not properly
encode login names. A remote attacker could possibly use this to expose
sensitive information. (CVE-2018-2588)
It was discovered that the DNS client implementation in OpenJDK did not
properly randomize source ports. A remote attacker could use this to spoof
responses to DNS queries made by Java applications. (CVE-2018-2599)
It was discovered that the Internationalization component of OpenJDK did
not restrict search paths when loading resource bundle classes. A local
attacker could use this to trick a user into
OSV
CVE-2018-2634: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS)
osv·2018-01-17·CVSS 6.8
CVE-2018-2634 [MEDIUM] CVE-2018-2634: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2018-04-02·CVSS 3.7
CVE-2018-2579 [LOW] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
It was discovered that a race condition existed in the cryptography
implementation in OpenJDK. An attacker could possibly use this to expose
sensitive information. (CVE-2018-2579)
It was discovered that the Hotspot component of OpenJDK did not properly
validate uses of the invokeinterface JVM instruction. An attacker could
possibly use this to access unauthorized resources. (CVE-2018-2582)
It was discovered that the LDAP implementation in OpenJDK did not properly
encode login names. A remote attacker could possibly use this to expose
sensitive information. (CVE-2018-2588)
It was discovered that the DNS client implementation in OpenJDK did not
properly randomize source ports. A remote attacker co
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2018-04-02·CVSS 3.7
CVE-2018-2579 [LOW] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
It was discovered that a race condition existed in the cryptography
implementation in OpenJDK. An attacker could possibly use this to expose
sensitive information. (CVE-2018-2579)
It was discovered that the LDAP implementation in OpenJDK did not properly
encode login names. A remote attacker could possibly use this to expose
sensitive information. (CVE-2018-2588)
It was discovered that the DNS client implementation in OpenJDK did not
properly randomize source ports. A remote attacker could use this to spoof
responses to DNS queries made by Java applications. (CVE-2018-2599)
It was discovered that the Internationalization component of OpenJDK did
not restrict search paths when loading resource bu
Red Hat
OpenJDK: use of global credentials for HTTP/SPNEGO (JGSS, 8186600)
vendor_redhat·2018-01-16·CVSS 6.8
CVE-2018-2634 [MEDIUM] CWE-284 OpenJDK: use of global credentials for HTTP/SPNEGO (JGSS, 8186600)
OpenJDK: use of global credentials for HTTP/SPNEGO (JGSS, 8186600)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start appli
Debian
CVE-2018-2634: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subc...
vendor_debian·2018·CVSS 6.8
CVE-2018-2634 [MEDIUM] CVE-2018-2634: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subc...
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code
Apache
Apache tika: CVE-2018-7489
vendor_apache·CVSS 9.8
CVE-2018-7489 [CRITICAL] Apache tika: CVE-2018-7489
Apache tika: CVE-2018-7489
and TIKA-2634 Jackson - Deserialization vulnerability Richard Cyganiak (notified Tika team) ?-1.17 PDFBOX-3919 Apache PDFBox - Infinite loop Hanno Böck and Andreas Bogk ?-1.16 TIKA-2115 Apache POI - OOM parsing OLE object Thomas Galla ?-1.15 COMPRESS-382 Commons Compress - OOM detecting corrupt LZMA Luís Filipe Nassif ?-1.15 COMPRESS-386 and TIKA-1631 Commons Compress - OOM detecting corrupt x-compress Pavel Micka ?-1.15 TIKA-2045 and TIKA-3442 Apache PDFBox - OOM in font caching Egbert ?-1.13 TIKA-1866 and TIKA-954 Apache POI - OOM in DOCX and PPTX because of bug in Piccolo parser Rob Tulloh and Shawn Johnson ?-1.13 TIKA-2040 GC-Overload and OOM in CHMParser Luís Filipe Nassif ?-1.13
No detection rules found.
No public exploits indexed.
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.securityfocus.com/bid/102592http://www.securitytracker.com/id/1040203https://access.redhat.com/errata/RHSA-2018:0095https://access.redhat.com/errata/RHSA-2018:0099https://access.redhat.com/errata/RHSA-2018:0100https://access.redhat.com/errata/RHSA-2018:0349https://access.redhat.com/errata/RHSA-2018:0351https://access.redhat.com/errata/RHSA-2018:0352https://access.redhat.com/errata/RHSA-2018:0458https://access.redhat.com/errata/RHSA-2018:0521https://access.redhat.com/errata/RHSA-2018:1463https://access.redhat.com/errata/RHSA-2018:1812https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/04/msg00003.htmlhttps://security.netapp.com/advisory/ntap-20180117-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03911en_ushttps://usn.ubuntu.com/3613-1/https://usn.ubuntu.com/3614-1/https://www.debian.org/security/2018/dsa-4144https://www.debian.org/security/2018/dsa-4166http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.securityfocus.com/bid/102592http://www.securitytracker.com/id/1040203https://access.redhat.com/errata/RHSA-2018:0095https://access.redhat.com/errata/RHSA-2018:0099https://access.redhat.com/errata/RHSA-2018:0100https://access.redhat.com/errata/RHSA-2018:0349https://access.redhat.com/errata/RHSA-2018:0351https://access.redhat.com/errata/RHSA-2018:0352https://access.redhat.com/errata/RHSA-2018:0458https://access.redhat.com/errata/RHSA-2018:0521https://access.redhat.com/errata/RHSA-2018:1463https://access.redhat.com/errata/RHSA-2018:1812https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2018/04/msg00003.htmlhttps://security.netapp.com/advisory/ntap-20180117-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03911en_ushttps://usn.ubuntu.com/3613-1/https://usn.ubuntu.com/3614-1/https://www.debian.org/security/2018/dsa-4144https://www.debian.org/security/2018/dsa-4166
2018-01-18
Published