cbcvebase.
CVE-2018-2657
published 2018-01-18

CVE-2018-2657: Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u171 and…

medium5.3CVSS 3.0
AVNACLPRNUINSUCNINAL
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u171 and 7u161; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, JRockit. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

Affected

20 ranges
VendorProductVersion rangeFixed in
debianopenjdk-8
hpxp7_command_view>= 8.6.2-01
hpxp_command_view>= 8.6.2-01
hpxp_p9000_command_view>= 8.6.2-01
oraclejdk
oraclejdk
oraclejre
oraclejre
oraclejrockit
oracle_corporationjava
oracle_corporationjava
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_eus
redhatenterprise_linux_workstation
redhatsatellite
redhatsatellite
redhatsatellite
schneider-electricstruxureware_data_center_expert< 7.6.07.6.0