CVE-2018-2942
published 2018-07-18CVE-2018-2942: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). Supported versions that are affected are Java SE: 7u181 and 8u172…
PriorityP343high8.3CVSS 3.1
AVNACHPRNUIRSCCHIHAH
EPSS
1.84%
76.5th percentile
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). Supported versions that are affected are Java SE: 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | — | — |
| netapp | e-series_santricity_os_controller | 11.0 – 11.70.1 | — |
| netapp | storage_replication_adapter_for_clustered_data_ontap | >= 9.7 | — |
| netapp | vasa_provider_for_clustered_data_ontap | >= 9.7 | — |
| netapp | virtual_storage_console | >= 9.7 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
CVSS provenance
nvdv3.18.3HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vendor_debian8.3LOW
vendor_redhat8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JDK: unspecified vulnerability fixed in 7u191 and 8u181 (Windows DLL)
vendor_redhat·2018-07-17·CVSS 8.3
CVE-2018-2942 [HIGH] JDK: unspecified vulnerability fixed in 7u191 and 8u181 (Windows DLL)
JDK: unspecified vulnerability fixed in 7u191 and 8u181 (Windows DLL)
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). Supported versions that are affected are Java SE: 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploit
Debian
CVE-2018-2942: openjdk-8 - Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows ...
vendor_debian·2018·CVSS 8.3
CVE-2018-2942 [HIGH] CVE-2018-2942: openjdk-8 - Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows ...
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). Supported versions that are affected are Java SE: 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using s
GHSA
GHSA-vc3h-7x28-w96r: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL)
ghsa_unreviewed·2022-05-13
CVE-2018-2942 [HIGH] GHSA-vc3h-7x28-w96r: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL)
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). Supported versions that are affected are Java SE: 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using s
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-3183 OpenJDK: Unrestricted access to scripting engine (Scripting, 8202936)
bugzilla·2018-10-15·CVSS 9.0
CVE-2018-3183 [CRITICAL] CVE-2018-3183 OpenJDK: Unrestricted access to scripting engine (Scripting, 8202936)
CVE-2018-3183 OpenJDK: Unrestricted access to scripting engine (Scripting, 8202936)
It was discovered that the Scripting component of OpenJDK did not properly restrict access to scripting engine via Global object's engine variable when using Security Manager or class filtering. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
Discussion:
Public now via Oracle CPU October 2018:
https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html#AppendixJAVA
The issue was fixed in Oracle JDK 11.0.1 and 8u191.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:2942 https://access.redhat.com/errata/RHSA-2018:2942
---
This issue has been addressed in the following products:
Re
Bugzilla
CVE-2018-2942 Oracle JDK: unspecified vulnerability fixed in 7u191 and 8u181 (Windows DLL)
bugzilla·2018-07-17·CVSS 8.3
CVE-2018-2942 [HIGH] CVE-2018-2942 Oracle JDK: unspecified vulnerability fixed in 7u191 and 8u181 (Windows DLL)
CVE-2018-2942 Oracle JDK: unspecified vulnerability fixed in 7u191 and 8u181 (Windows DLL)
Oracle Java SE 7u191 and 8u181 fixes an unspecified vulnerability in the Windows DLL component (CVE-2018-2942). Upstream has CVSS scored this issue as: 8.3/CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
External Reference:
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html#AppendixJAVA
Discussion:
Windows DLL issue can only be applicable to Oracle Java SE for Microsoft Windows and not applicable to version for Linux.
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securityfocus.com/bid/104781http://www.securitytracker.com/id/1041302https://security.netapp.com/advisory/ntap-20180726-0001/http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securityfocus.com/bid/104781http://www.securitytracker.com/id/1041302https://security.netapp.com/advisory/ntap-20180726-0001/
2018-07-18
Published