CVE-2018-3136

CWE-34711 documents8 sources
Severity
3.4LOW
EPSS
0.4%
top 39.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17
Latest updateMay 13

Description

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, a

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:NExploitability: 1.6 | Impact: 1.4

Affected Packages12 packages

CVEListV5oracle_corporation/java; Java SE Embedded: 8u181, Java SE: 6u201, 7u191, 8u181, 11+1
NVDoracle/jdk4 versions+3
NVDoracle/jre4 versions+3
NVDhp/xp7_command_view< 8.6.3-00
Ubuntuopenjdk-7< 7u181-2.6.14-0ubuntu0.3

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 16.04, 18.04, 18.10, Enterprise Linux 7.6, 7.5

Patches

🔴Vulnerability Details

5
GHSA
GHSA-f6rv-hvw7-6w6f: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security)2022-05-13
OSV
openjdk-7 vulnerabilities2018-11-16
OSV
openjdk-8, openjdk-lts vulnerabilities2018-10-30
CVEList
CVE-2018-3136: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security)2018-10-17
OSV
CVE-2018-3136: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security)2018-10-17

📋Vendor Advisories

4
Ubuntu
OpenJDK 7 vulnerabilities2018-11-16
Ubuntu
OpenJDK vulnerabilities2018-10-30
Red Hat
OpenJDK: Incorrect handling of unsigned attributes in signed Jar manifests (Security, 8194534)2018-10-16
Debian
CVE-2018-3136: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subc...2018

💬Community

1
Bugzilla
CVE-2018-3136 OpenJDK: Incorrect handling of unsigned attributes in signed Jar manifests (Security, 8194534)2018-10-16