5.3

CVE-2018-2657

Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u171 and 7u161; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, JRockit. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

Data is provided by the National Vulnerability Database (NVD)
OracleJdk Version1.6.0 Updateupdate171
OracleJdk Version1.7.0 Updateupdate161
OracleJre Version1.6.0 Updateupdate171
OracleJre Version1.7.0 Updateupdate161
OracleJrockit Versionr28.3.16
RedhatSatellite Version5.6
RedhatSatellite Version5.7
RedhatSatellite Version5.8
HpXp Command View SwEditionadvanced Version >= 8.6.2-01
HpXp P9000 Command View SwEditionadvanced Version >= 8.6.2-01
HpXp7 Command View SwEditionadvanced Version >= 8.6.2-01
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.56% 0.672
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P