CVE-2018-2579 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152, and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. EPSS estimates a 4.11% chance of exploitation in the next 30 days.

## Description

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152, and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).

## Metrics

CVSS 3.13.7/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS Probability 4.11%

89.5th percentile

Probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Affected Software

| Vendor | Product | Versions | Update |
| --- | --- | --- | --- |
| Oracle | Jdk | 1.6.0 | Update171 |
| Oracle | Jdk | 1.7.0 | Update161 |
| Oracle | Jdk | 1.8.0 | Update152 |
| Oracle | Jdk | 9.0.1 | — |
| Oracle | Jre | 1.6.0 | Update171 |
| Oracle | Jre | 1.7.0 | Update161 |
| Oracle | Jre | 1.8.0 | Update152 |
| Oracle | Jre | 9.0.1 | — |
| Oracle | Jrockit | r28.3.16 | — |
| Redhat | Satellite | 5.6 | — |
| Redhat | Satellite | 5.7 | — |
| Redhat | Satellite | 5.8 | — |
| Redhat | Enterprise Linux Desktop | 6.0 | — |
| Redhat | Enterprise Linux Desktop | 7.0 | — |
| Redhat | Enterprise Linux Server | 6.0 | — |
| Redhat | Enterprise Linux Server | 7.0 | — |
| Redhat | Enterprise Linux Server Aus | 7.4 | — |
| Redhat | Enterprise Linux Server Aus | 7.6 | — |
| Redhat | Enterprise Linux Server Eus | 7.4 | — |
| Redhat | Enterprise Linux Server Eus | 7.5 | — |
| Redhat | Enterprise Linux Server Eus | 7.6 | — |
| Redhat | Enterprise Linux Server Tus | 7.4 | — |
| Redhat | Enterprise Linux Server Tus | 7.6 | — |
| Redhat | Enterprise Linux Workstation | 6.0 | — |
| Redhat | Enterprise Linux Workstation | 7.0 | — |
| Debian | Debian Linux | 7.0 | — |
| Debian | Debian Linux | 8.0 | — |
| Debian | Debian Linux | 9.0 | — |
| Canonical | Ubuntu Linux | 14.04 | — |
| Canonical | Ubuntu Linux | 16.04 | — |
| Canonical | Ubuntu Linux | 17.10 | — |
| Schneider-Electric | Struxureware Data Center Expert | < 7.6.0 | — |
| Hp | Xp Command View | >= 8.6.2-01 | — |
| Hp | Xp P9000 Command View | >= 8.6.2-01 | — |
| Hp | Xp7 Command View | >= 8.6.2-01 | — |

## References

- [Oracle Security Advisory](https://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html) Patch, Vendor Advisory
- [Security Focus](https://www.securityfocus.com/bid/102663) Broken Link, Third Party Advisory, VDB Entry
- [Security Tracker](https://www.securitytracker.com/id/1040203) Broken Link, Third Party Advisory, VDB Entry
- [Red Hat Errata](https://access.redhat.com/errata/RHSA-2018:0095) Third Party Advisory
- [Red Hat Errata](https://access.redhat.com/errata/RHSA-2018:0099) Third Party Advisory
- [Red Hat Errata](https://access.redhat.com/errata/RHSA-2018:0100) Third Party Advisory
- [Red Hat Errata](https://access.redhat.com/errata/RHSA-2018:0115) Third Party Advisory
- [Red Hat Errata](https://access.redhat.com/errata/RHSA-2018:0349) Third Party Advisory
- [Red Hat Errata](https://access.redhat.com/errata/RHSA-2018:0351) Third Party Advisory
- [Red Hat Errata](https://access.redhat.com/errata/RHSA-2018:0352) Third Party Advisory
- [Red Hat Errata](https://access.redhat.com/errata/RHSA-2018:0458) Third Party Advisory
- [Red Hat Errata](https://access.redhat.com/errata/RHSA-2018:0521) Third Party Advisory
- [Red Hat Errata](https://access.redhat.com/errata/RHSA-2018:1463) Third Party Advisory
- [Red Hat Errata](https://access.redhat.com/errata/RHSA-2018:1812) Third Party Advisory
- [Ecostruxure Security Fixes](https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0) Third Party Advisory
- [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2018/04/msg00003.html) Mailing List, Third Party Advisory
- [NetApp Advisory](https://security.netapp.com/advisory/ntap-20180117-0001/) Third Party Advisory
- [HPE Support Document](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03911en_us) Third Party Advisory
- [Ubuntu Security Notice](https://usn.ubuntu.com/3613-1/) Third Party Advisory
- [Ubuntu Security Notice](https://usn.ubuntu.com/3614-1/) Third Party Advisory
- [Debian Security](https://www.debian.org/security/2018/dsa-4144) Third Party Advisory
- [Debian Security](https://www.debian.org/security/2018/dsa-4166) Third Party Advisory

## Timeline

Published Jan 18, 2018

Last Modified Jun 17, 2026

Status Modified

## Frequently Asked Questions

**What is CVE-2018-2579?**  
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152, and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16.

**How severe is CVE-2018-2579?**  
CVE-2018-2579 has a CVSS score of 3.7/10 (LOW severity). The EPSS model estimates a 4.11% probability of exploitation in the next 30 days.

**How do I fix CVE-2018-2579?**  
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.
