7.5
CVE-2018-1517
- EPSS 3.98%
- Veröffentlicht 20.08.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 03:59:57
- Erkennungen
A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data. IBM X-Force ID: 141681.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Software Development Kit Version 6 Update service_refresh_16 SwEdition java_technology
Ibm ≫ Software Development Kit Version 6.0 SwEdition java_technology
Ibm ≫ Software Development Kit Version 6r1 Update service_refresh_8 SwEdition java_technology
Ibm ≫ Software Development Kit Version 7 Update service_refresh_10 SwEdition java_technology
Ibm ≫ Software Development Kit Version 7.0 SwEdition java_technology
Ibm ≫ Software Development Kit Version 7r1 Update service_refresh_4 SwEdition java_technology
Ibm ≫ Software Development Kit Version 8 Update service_refresh_5 SwEdition java_technology
Ibm ≫ Software Development Kit Version 8.0 SwEdition java_technology
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.98% | 0.892 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
| IBM | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://access.redhat.com/errata/RHSA-2018:2568
https://access.redhat.com/errata/RHSA-2018:2575
https://access.redhat.com/errata/RHSA-2018:2713
https://access.redhat.com/errata/RHSA-2018:2569
https://access.redhat.com/errata/RHSA-2018:2576
https://access.redhat.com/errata/RHSA-2018:2712
http://www.ibm.com/support/docview.wss?uid=ibm10719653
http://www.securityfocus.com/bid/105117
https://exchange.xforce.ibmcloud.com/vulnerabilities/141681