CVE-2018-2800
published 2018-04-19CVE-2018-2800: Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u181, 7u171 and…
PriorityP424medium4.2CVSS 3.0
AVNACHPRNUIRSUCLILAN
EPSS
5.41%
91.9th percentile
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u181, 7u171 and 8u162; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, JRockit accessible data as well as unauthorized read access to a subset of Java SE, JRockit accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjdk-8 | < openjdk-8 8u171-b11-1 (sid) | openjdk-8 8u171-b11-1 (sid) |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jrockit | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.04.2MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv4.2MEDIUM
vendor_cisco7.5HIGH
vendor_debian4.2MEDIUM
vendor_redhat4.2MEDIUM
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pm9w-699m-qvpr: Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI)
ghsa_unreviewed·2022-05-13
CVE-2018-2800 [MEDIUM] GHSA-pm9w-699m-qvpr: Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI)
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u181, 7u171 and 8u162; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, JRockit accessible data as well as unauthorized read access to a subset of Java SE, JRockit accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted
OSV
openjdk-7 vulnerabilities
osv·2018-06-21·CVSS 3.1
CVE-2018-2790 [LOW] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
It was discovered that the Security component of OpenJDK did not correctly
perform merging of multiple sections for the same file listed in JAR
archive file manifests. An attacker could possibly use this to modify
attributes in a manifest without invalidating the signature.
(CVE-2018-2790)
Francesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi
discovered that the Security component of OpenJDK did not restrict which
classes could be used when deserializing keys from the JCEKS key stores. An
attacker could use this to specially craft a JCEKS key store to execute
arbitrary code. (CVE-2018-2794)
It was discovered that the Security component of OpenJDK in some situations
did not properly limit the amount of memory allocated when performing
deseri
OSV
openjdk-8 vulnerabilities
osv·2018-05-11·CVSS 3.1
CVE-2018-2790 [LOW] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
It was discovered that the Security component of OpenJDK did not
correctly perform merging of multiple sections for the same file listed
in JAR archive file manifests. An attacker could possibly use this to
modify attributes in a manifest without invalidating the signature.
(CVE-2018-2790)
Francesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi
discovered that the Security component of OpenJDK did not restrict which
classes could be used when deserializing keys from the JCEKS key stores. An
attacker could use this to specially craft a JCEKS key store to execute
arbitrary code. (CVE-2018-2794)
It was discovered that the Security component of OpenJDK in some situations
did not properly limit the amount of memory allocated when performing
deseri
OSV
CVE-2018-2800: Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI)
osv·2018-04-18·CVSS 4.2
CVE-2018-2800 [MEDIUM] CVE-2018-2800: Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI)
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u181, 7u171 and 8u162; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, JRockit accessible data as well as unauthorized read access to a subset of Java SE, JRockit accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted
Cisco
Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points Denial of Service Vulnerability
vendor_cisco·2018-10-17·CVSS 5.8
CVE-2018-0381 [MEDIUM] CWE-667 Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points Denial of Service Vulnerability
Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points Denial of Service Vulnerability
A vulnerability in the Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points (APs) software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
The vulnerability is due to a deadlock condition that may occur when an affected AP attempts to dequeue aggregated traffic that is destined to an attacker-controlled wireless client. An attacker who can successfully transition between multiple Service Set Identifiers (SSIDs) hosted on the same AP while replicating the required traffic patterns could trigger the deadlock condition. A watchdog timer that detects the condition will trigger a reload of th
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2018-06-21·CVSS 3.1
CVE-2018-2790 [LOW] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
It was discovered that the Security component of OpenJDK did not correctly
perform merging of multiple sections for the same file listed in JAR
archive file manifests. An attacker could possibly use this to modify
attributes in a manifest without invalidating the signature.
(CVE-2018-2790)
Francesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi
discovered that the Security component of OpenJDK did not restrict which
classes could be used when deserializing keys from the JCEKS key stores. An
attacker could use this to specially craft a JCEKS key store to execute
arbitrary code. (CVE-2018-2794)
It was discovered that the Security component of OpenJDK in some situations
did not pr
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2018-05-11·CVSS 3.1
CVE-2018-2790 [LOW] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
It was discovered that the Security component of OpenJDK did not
correctly perform merging of multiple sections for the same file listed
in JAR archive file manifests. An attacker could possibly use this to
modify attributes in a manifest without invalidating the signature.
(CVE-2018-2790)
Francesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi
discovered that the Security component of OpenJDK did not restrict which
classes could be used when deserializing keys from the JCEKS key stores. An
attacker could use this to specially craft a JCEKS key store to execute
arbitrary code. (CVE-2018-2794)
It was discovered that the Security component of OpenJDK in some situations
did not pr
Cisco
Cisco Aironet 1800, 2800, and 3800 Series Access Points Secure Shell Privilege Escalation Vulnerability
vendor_cisco·2018-05-02·CVSS 7.5
CVE-2018-0226 [HIGH] CWE-255 Cisco Aironet 1800, 2800, and 3800 Series Access Points Secure Shell Privilege Escalation Vulnerability
Cisco Aironet 1800, 2800, and 3800 Series Access Points Secure Shell Privilege Escalation Vulnerability
A vulnerability in the assignment and management of default user accounts for Secure Shell (SSH) access to Cisco Aironet 1800, 2800, and 3800 Series Access Points that are running Cisco Mobility Express Software could allow an authenticated, remote attacker to gain elevated privileges on an affected access point.
The vulnerability exists because the Cisco Mobility Express controller of the affected software configures the default SSH user account for an access point to be the first SSH user account that was created for the Mobility Express controller, if an administrator added user accounts directly to the controller instead of using the default configuration or the SSH username creatio
Cisco
Cisco Aironet Access Points Central Web Authentication FlexConnect Client ACL Bypass Vulnerability
vendor_cisco·2018-05-02·CVSS 4.1
CVE-2018-0250 [MEDIUM] CWE-693 Cisco Aironet Access Points Central Web Authentication FlexConnect Client ACL Bypass Vulnerability
Cisco Aironet Access Points Central Web Authentication FlexConnect Client ACL Bypass Vulnerability
A vulnerability in Central Web Authentication (CWA) with FlexConnect Access Points (APs) for Cisco Aironet 1560, 1810, 1810w, 1815, 1830, 1850, 2800, and 3800 Series APs could allow an authenticated, adjacent attacker to bypass a configured FlexConnect access control list (ACL).
The vulnerability is due to the AP ignoring the ACL download from the client during authentication. An attacker could exploit this vulnerability by connecting to the targeted device with a vulnerable configuration. A successful exploit could allow the attacker to bypass a configured client FlexConnect ACL.
There are workarounds that address this vulnerability.
This advisory is available at the following link:
http
Red Hat
OpenJDK: RMI HTTP transport enabled by default (RMI, 8193833)
vendor_redhat·2018-04-17·CVSS 4.2
CVE-2018-2800 [MEDIUM] OpenJDK: RMI HTTP transport enabled by default (RMI, 8193833)
OpenJDK: RMI HTTP transport enabled by default (RMI, 8193833)
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u181, 7u171 and 8u162; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, JRockit accessible data as well as unauthorized read access to a subset of Java SE, JRockit accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component wi
Debian
CVE-2018-2800: openjdk-8 - Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent:...
vendor_debian·2018·CVSS 4.2
CVE-2018-2800 [MEDIUM] CVE-2018-2800: openjdk-8 - Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent:...
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u181, 7u171 and 8u162; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, JRockit accessible data as well as unauthorized read access to a subset of Java SE, JRockit accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted
Cisco
Cisco Aironet 1800, 2800, and 3800 Series Access Points Secure Shell Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0226 Cisco Aironet 1800, 2800, and 3800 Series Access Points Secure Shell Privilege Escalation Vulnerability
CVE-2018-0226: Cisco Aironet 1800, 2800, and 3800 Series Access Points Secure Shell Privilege Escalation Vulnerability
A vulnerability in the assignment and management of default user accounts for Secure Shell (SSH) access to Cisco Aironet 1800, 2800, and 3800 Series Access Points that are running Cisco Mobility Express Software could allow an authenticated, remote attacker to gain elevated privileges on an affected access point. The vulnerability exists because the Cisco Mobility Express controller of the affected software configures the default SSH user account for an access point to be the first SSH user account that was created for the Mobility Express controller, if an administrator added user accounts directly to the controller instead of using the default configuration or the SSH us
Cisco
Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0381 Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points Denial of Service Vulnerability
CVE-2018-0381: Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points Denial of Service Vulnerability
A vulnerability in the Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points (APs) software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a deadlock condition that may occur when an affected AP attempts to dequeue aggregated traffic that is destined to an attacker-controlled wireless client. An attacker who can successfully transition between multiple Service Set Identifiers (SSIDs) hosted on the same AP while replicating the required traffic patterns could trigger the deadlock condition. A watchdog timer that detects the condition will trigger
Cisco
Cisco Aironet Access Points Central Web Authentication FlexConnect Client ACL Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0250 Cisco Aironet Access Points Central Web Authentication FlexConnect Client ACL Bypass Vulnerability
CVE-2018-0250: Cisco Aironet Access Points Central Web Authentication FlexConnect Client ACL Bypass Vulnerability
A vulnerability in Central Web Authentication (CWA) with FlexConnect Access Points (APs) for Cisco Aironet 1560, 1810, 1810w, 1815, 1830, 1850, 2800, and 3800 Series APs could allow an authenticated, adjacent attacker to bypass a configured FlexConnect access control list (ACL). The vulnerability is due to the AP ignoring the ACL download from the client during authentication. An attacker could exploit this vulnerability by connecting to the targeted device with a vulnerable configuration. A successful exploit could allow the attacker to bypass a configured client FlexConnect ACL. There are
CVSS: 3.0
CWE: CWE-693, CWE-693
Bug IDs: CSCve17756
No detection rules found.
No public exploits indexed.
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.securityfocus.com/bid/103849http://www.securitytracker.com/id/1040697https://access.redhat.com/errata/RHSA-2018:1188https://access.redhat.com/errata/RHSA-2018:1191https://access.redhat.com/errata/RHSA-2018:1201https://access.redhat.com/errata/RHSA-2018:1202https://access.redhat.com/errata/RHSA-2018:1203https://access.redhat.com/errata/RHSA-2018:1204https://access.redhat.com/errata/RHSA-2018:1205https://access.redhat.com/errata/RHSA-2018:1206https://access.redhat.com/errata/RHSA-2018:1270https://access.redhat.com/errata/RHSA-2018:1278https://access.redhat.com/errata/RHSA-2018:1721https://access.redhat.com/errata/RHSA-2018:1722https://access.redhat.com/errata/RHSA-2018:1723https://access.redhat.com/errata/RHSA-2018:1724https://access.redhat.com/errata/RHSA-2018:1974https://access.redhat.com/errata/RHSA-2018:1975https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://security.gentoo.org/glsa/201903-14https://security.netapp.com/advisory/ntap-20180419-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03857en_ushttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03915en_ushttps://usn.ubuntu.com/3644-1/https://usn.ubuntu.com/3691-1/https://www.debian.org/security/2018/dsa-4185https://www.debian.org/security/2018/dsa-4225http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.securityfocus.com/bid/103849http://www.securitytracker.com/id/1040697https://access.redhat.com/errata/RHSA-2018:1188https://access.redhat.com/errata/RHSA-2018:1191https://access.redhat.com/errata/RHSA-2018:1201https://access.redhat.com/errata/RHSA-2018:1202https://access.redhat.com/errata/RHSA-2018:1203https://access.redhat.com/errata/RHSA-2018:1204https://access.redhat.com/errata/RHSA-2018:1205https://access.redhat.com/errata/RHSA-2018:1206https://access.redhat.com/errata/RHSA-2018:1270https://access.redhat.com/errata/RHSA-2018:1278https://access.redhat.com/errata/RHSA-2018:1721https://access.redhat.com/errata/RHSA-2018:1722https://access.redhat.com/errata/RHSA-2018:1723https://access.redhat.com/errata/RHSA-2018:1724https://access.redhat.com/errata/RHSA-2018:1974https://access.redhat.com/errata/RHSA-2018:1975https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://security.gentoo.org/glsa/201903-14https://security.netapp.com/advisory/ntap-20180419-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03857en_ushttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03915en_ushttps://usn.ubuntu.com/3644-1/https://usn.ubuntu.com/3691-1/https://www.debian.org/security/2018/dsa-4185https://www.debian.org/security/2018/dsa-4225
2018-04-19
Published