7.5

CVE-2018-1517

A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data. IBM X-Force ID: 141681.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Software Development Kit Version 6 Update service_refresh_16 SwEdition java_technology
Ibm ≫ Software Development Kit Version 6.0 SwEdition java_technology
Ibm ≫ Software Development Kit Version 6r1 Update service_refresh_8 SwEdition java_technology
Ibm ≫ Software Development Kit Version 7 Update service_refresh_10 SwEdition java_technology
Ibm ≫ Software Development Kit Version 7.0 SwEdition java_technology
Ibm ≫ Software Development Kit Version 7r1 Update service_refresh_4 SwEdition java_technology
Ibm ≫ Software Development Kit Version 8 Update service_refresh_5 SwEdition java_technology
Ibm ≫ Software Development Kit Version 8.0 SwEdition java_technology
Redhat ≫ Satellite Version 5.6
Redhat ≫ Satellite Version 5.7
Redhat ≫ Satellite Version 5.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.98% 0.892
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
IBM 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://access.redhat.com/errata/RHSA-2018:2568
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2575
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2713
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2569
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2576
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2712
Third Party Advisory
http://www.ibm.com/support/docview.wss?uid=ibm10719653
Vendor Advisory
http://www.securityfocus.com/bid/105117
Third Party Advisory
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/141681
Vendor Advisory
VDB Entry