CVE-2018-2579: Jdk Vulnerability (CVSS 3.7) — Fix & Details
CVE-2018-2579 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152, and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. EPSS estimates a 4.11% chance of exploitation in the next 30 days.
Description
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152, and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Metrics
CVSS 3.13.7/10
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Probability 4.11%
89.5th percentile
Probability of exploitation in the next 30 days. Learn more
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Oracle | Jdk | 1.6.0 | Update171 |
| Oracle | Jdk | 1.7.0 | Update161 |
| Oracle | Jdk | 1.8.0 | Update152 |
| Oracle | Jdk | 9.0.1 | — |
| Oracle | Jre | 1.6.0 | Update171 |
| Oracle | Jre | 1.7.0 | Update161 |
| Oracle | Jre | 1.8.0 | Update152 |
| Oracle | Jre | 9.0.1 | — |
| Oracle | Jrockit | r28.3.16 | — |
| Redhat | Satellite | 5.6 | — |
| Redhat | Satellite | 5.7 | — |
| Redhat | Satellite | 5.8 | — |
| Redhat | Enterprise Linux Desktop | 6.0 | — |
| Redhat | Enterprise Linux Desktop | 7.0 | — |
| Redhat | Enterprise Linux Server | 6.0 | — |
| Redhat | Enterprise Linux Server | 7.0 | — |
| Redhat | Enterprise Linux Server Aus | 7.4 | — |
| Redhat | Enterprise Linux Server Aus | 7.6 | — |
| Redhat | Enterprise Linux Server Eus | 7.4 | — |
| Redhat | Enterprise Linux Server Eus | 7.5 | — |
| Redhat | Enterprise Linux Server Eus | 7.6 | — |
| Redhat | Enterprise Linux Server Tus | 7.4 | — |
| Redhat | Enterprise Linux Server Tus | 7.6 | — |
| Redhat | Enterprise Linux Workstation | 6.0 | — |
| Redhat | Enterprise Linux Workstation | 7.0 | — |
| Debian | Debian Linux | 7.0 | — |
| Debian | Debian Linux | 8.0 | — |
| Debian | Debian Linux | 9.0 | — |
| Canonical | Ubuntu Linux | 14.04 | — |
| Canonical | Ubuntu Linux | 16.04 | — |
| Canonical | Ubuntu Linux | 17.10 | — |
| Schneider-Electric | Struxureware Data Center Expert | < 7.6.0 | — |
| Hp | Xp Command View | >= 8.6.2-01 | — |
| Hp | Xp P9000 Command View | >= 8.6.2-01 | — |
| Hp | Xp7 Command View | >= 8.6.2-01 | — |
References
- Oracle Security Advisory Patch, Vendor Advisory
- Security Focus Broken Link, Third Party Advisory, VDB Entry
- Security Tracker Broken Link, Third Party Advisory, VDB Entry
- Red Hat Errata Third Party Advisory
- Red Hat Errata Third Party Advisory
- Red Hat Errata Third Party Advisory
- Red Hat Errata Third Party Advisory
- Red Hat Errata Third Party Advisory
- Red Hat Errata Third Party Advisory
- Red Hat Errata Third Party Advisory
- Red Hat Errata Third Party Advisory
- Red Hat Errata Third Party Advisory
- Red Hat Errata Third Party Advisory
- Red Hat Errata Third Party Advisory
- Ecostruxure Security Fixes Third Party Advisory
- Debian LTS Announce Mailing List, Third Party Advisory
- NetApp Advisory Third Party Advisory
- HPE Support Document Third Party Advisory
- Ubuntu Security Notice Third Party Advisory
- Ubuntu Security Notice Third Party Advisory
- Debian Security Third Party Advisory
- Debian Security Third Party Advisory
Timeline
Published Jan 18, 2018
Last Modified Jun 17, 2026
Status Modified
Frequently Asked Questions
What is CVE-2018-2579?
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152, and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16.
How severe is CVE-2018-2579?
CVE-2018-2579 has a CVSS score of 3.7/10 (LOW severity). The EPSS model estimates a 4.11% probability of exploitation in the next 30 days.
How do I fix CVE-2018-2579?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.