CVE-2018-2657
published 2018-01-18CVE-2018-2657: Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u171 and…
PriorityP433medium5.3CVSS 3.0
AVNACLPRNUINSUCNINAL
EPSS
7.52%
93.8th percentile
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u171 and 7u161; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, JRockit. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | — | — |
| hp | xp7_command_view | >= 8.6.2-01 | — |
| hp | xp_command_view | >= 8.6.2-01 | — |
| hp | xp_p9000_command_view | >= 8.6.2-01 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jrockit | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | satellite | — | — |
| redhat | satellite | — | — |
| redhat | satellite | — | — |
| schneider-electric | struxureware_data_center_expert | < 7.6.0 | 7.6.0 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JDK: unspecified vulnerability fixed in 6u181 and 7u171 (Serialization)
vendor_redhat·2018-01-16·CVSS 5.3
CVE-2018-2657 [MEDIUM] JDK: unspecified vulnerability fixed in 6u181 and 7u171 (Serialization)
JDK: unspecified vulnerability fixed in 6u181 and 7u171 (Serialization)
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u171 and 7u161; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, JRockit. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts)
Debian
CVE-2018-2657: openjdk-8 - Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent:...
vendor_debian·2018·CVSS 5.3
CVE-2018-2657 [MEDIUM] CVE-2018-2657: openjdk-8 - Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent:...
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u171 and 7u161; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, JRockit. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Scope: loc
GHSA
GHSA-qq7j-frwj-qh26: Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization)
ghsa_unreviewed·2022-05-13
CVE-2018-2657 [MEDIUM] GHSA-qq7j-frwj-qh26: Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization)
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u171 and 7u161; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, JRockit. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-19839 libsass: Heap-based buffer over-read in the handle_error function resulting in a denial of service
bugzilla·2019-01-31·CVSS 6.5
CVE-2018-19839 [MEDIUM] CVE-2018-19839 libsass: Heap-based buffer over-read in the handle_error function resulting in a denial of service
CVE-2018-19839 libsass: Heap-based buffer over-read in the handle_error function resulting in a denial of service
In LibSass prior to 3.5.5, the function handle_error in sass_context.cpp allows attackers to cause a denial-of-service resulting from a heap-based buffer over-read via a crafted sass file.
Upstream issue:
https://github.com/sass/libsass/issues/2657
Upstream patch:
https://github.com/sass/libsass/pull/2767/commits/a2dff1b59ea8c8ec10680f9e8e5593e4b38554a1
Upstream pull request:
https://github.com/sass/libsass/pull/2767
Discussion:
Created libsass tracking bugs for this issue:
Affects: epel-7 [bug 1671396]
Affects: fedora-all [bug 1671395]
Bugzilla
CVE-2018-2657 Oracle JDK: unspecified vulnerability fixed in 6u181 and 7u171 (Serialization)
bugzilla·2018-01-17·CVSS 5.3
CVE-2018-2657 [MEDIUM] CVE-2018-2657 Oracle JDK: unspecified vulnerability fixed in 6u181 and 7u171 (Serialization)
CVE-2018-2657 Oracle JDK: unspecified vulnerability fixed in 6u181 and 7u171 (Serialization)
Oracle Java SE 6u181 and 7u171 fixes an unspecified vulnerability in the Serialization component (CVE-2018-2657). Upstream has CVSS scored this issue as: 5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
External Reference:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 7
Oracle Java for Red Hat Enterprise Linux 6
Via RHSA-2018:0100 https://access.redhat.com/errata/RHSA-2018:0100
---
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 7
Oracle Java for Red Hat Enterprise Linux 6
Via RHSA-2018:0
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.securityfocus.com/bid/102629http://www.securitytracker.com/id/1040203https://access.redhat.com/errata/RHSA-2018:0100https://access.redhat.com/errata/RHSA-2018:0115https://access.redhat.com/errata/RHSA-2018:0458https://access.redhat.com/errata/RHSA-2018:0521https://access.redhat.com/errata/RHSA-2018:1463https://access.redhat.com/errata/RHSA-2018:1812https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://security.netapp.com/advisory/ntap-20180117-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03911en_ushttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.securityfocus.com/bid/102629http://www.securitytracker.com/id/1040203https://access.redhat.com/errata/RHSA-2018:0100https://access.redhat.com/errata/RHSA-2018:0115https://access.redhat.com/errata/RHSA-2018:0458https://access.redhat.com/errata/RHSA-2018:0521https://access.redhat.com/errata/RHSA-2018:1463https://access.redhat.com/errata/RHSA-2018:1812https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://security.netapp.com/advisory/ntap-20180117-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03911en_us
2018-01-18
Published