CVE-2018-2579: Jdk Vulnerability (CVSS 3.7) — Fix & Details

CVE-2018-2579 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152, and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. EPSS estimates a 4.11% chance of exploitation in the next 30 days.

Description

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152, and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).

Metrics

CVSS 3.13.7/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS Probability 4.11%

89.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Vendor Product Versions Update
Oracle Jdk 1.6.0 Update171
Oracle Jdk 1.7.0 Update161
Oracle Jdk 1.8.0 Update152
Oracle Jdk 9.0.1
Oracle Jre 1.6.0 Update171
Oracle Jre 1.7.0 Update161
Oracle Jre 1.8.0 Update152
Oracle Jre 9.0.1
Oracle Jrockit r28.3.16
Redhat Satellite 5.6
Redhat Satellite 5.7
Redhat Satellite 5.8
Redhat Enterprise Linux Desktop 6.0
Redhat Enterprise Linux Desktop 7.0
Redhat Enterprise Linux Server 6.0
Redhat Enterprise Linux Server 7.0
Redhat Enterprise Linux Server Aus 7.4
Redhat Enterprise Linux Server Aus 7.6
Redhat Enterprise Linux Server Eus 7.4
Redhat Enterprise Linux Server Eus 7.5
Redhat Enterprise Linux Server Eus 7.6
Redhat Enterprise Linux Server Tus 7.4
Redhat Enterprise Linux Server Tus 7.6
Redhat Enterprise Linux Workstation 6.0
Redhat Enterprise Linux Workstation 7.0
Debian Debian Linux 7.0
Debian Debian Linux 8.0
Debian Debian Linux 9.0
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 17.10
Schneider-Electric Struxureware Data Center Expert < 7.6.0
Hp Xp Command View >= 8.6.2-01
Hp Xp P9000 Command View >= 8.6.2-01
Hp Xp7 Command View >= 8.6.2-01

References

Timeline

Published Jan 18, 2018

Last Modified Jun 17, 2026

Status Modified

Frequently Asked Questions

What is CVE-2018-2579?
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152, and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16.

How severe is CVE-2018-2579?
CVE-2018-2579 has a CVSS score of 3.7/10 (LOW severity). The EPSS model estimates a 4.11% probability of exploitation in the next 30 days.

How do I fix CVE-2018-2579?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.