CVE-2018-3169

Severity
8.3HIGH
EPSS
0.5%
top 33.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17
Latest updateMay 13

Description

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks m

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 1.6 | Impact: 6.0

Affected Packages8 packages

NVDoracle/jdk1.7.0, 1.8.0, 11.0.0+2
NVDoracle/jre1.7.0, 1.8.0, 11.0.0+2
NVDhp/xp7_command_view< 8.6.3-00
Debianopenjdk-11< 11.0.1+13-1
NVDredhat/satellite5.6, 5.7, 5.8+2

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 18.10, Enterprise Linux 7.6, 7.5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2q2m-64x8-6r9q: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot)2022-05-13
CVEList
CVE-2018-3169: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot)2018-10-17
OSV
CVE-2018-3169: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot)2018-10-17

📋Vendor Advisories

4
Ubuntu
OpenJDK 7 vulnerabilities2018-11-16
Ubuntu
OpenJDK vulnerabilities2018-10-30
Red Hat
OpenJDK: Improper field access checks (Hotspot, 8199226)2018-10-16
Debian
CVE-2018-3169: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subc...2018

💬Community

1
Bugzilla
CVE-2018-3169 OpenJDK: Improper field access checks (Hotspot, 8199226)2018-10-15
CVE-2018-3169 (HIGH CVSS 8.3) | Vulnerability in the Java SE | cvebase.io