CVE-2018-1417

Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code running under a security manager to elevate its privileges. IBM X-Force ID: 138823.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
Affected Products (NVD)
VendorProductVersion
ibmjava_sdk
6.0.0.0
ibmjava_sdk
6.1.0.0
ibmjava_sdk
7.0.0.0
ibmjava_sdk
7.1.0.0
ibmjava_sdk
8.0.0.0
𝑥
= Vulnerable software versions
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
java-1.7.1-ibm
RHEL 6
1:1.7.1.4.20-1jpp.3.el6_9
fixed
RHEL 7
1:1.7.1.4.20-1jpp.1.el7
fixed
java-1.7.1-ibm-demo
RHEL 6
1:1.7.1.4.20-1jpp.3.el6_9
fixed
RHEL 7
1:1.7.1.4.20-1jpp.1.el7
fixed
java-1.7.1-ibm-devel
RHEL 6
1:1.7.1.4.20-1jpp.3.el6_9
fixed
RHEL 7
1:1.7.1.4.20-1jpp.1.el7
fixed
java-1.7.1-ibm-jdbc
RHEL 6
1:1.7.1.4.20-1jpp.3.el6_9
fixed
RHEL 7
1:1.7.1.4.20-1jpp.1.el7
fixed
java-1.7.1-ibm-plugin
RHEL 6
1:1.7.1.4.20-1jpp.3.el6_9
fixed
RHEL 7
1:1.7.1.4.20-1jpp.1.el7
fixed
java-1.7.1-ibm-src
RHEL 6
1:1.7.1.4.20-1jpp.3.el6_9
fixed
RHEL 7
1:1.7.1.4.20-1jpp.1.el7
fixed
java-1.8.0-ibm
RHEL 6
1:1.8.0.5.10-1jpp.1.el6_9
fixed
RHEL 7
1:1.8.0.5.10-1jpp.1.el7
fixed
java-1.8.0-ibm-demo
RHEL 6
1:1.8.0.5.10-1jpp.1.el6_9
fixed
RHEL 7
1:1.8.0.5.10-1jpp.1.el7
fixed
java-1.8.0-ibm-devel
RHEL 6
1:1.8.0.5.10-1jpp.1.el6_9
fixed
RHEL 7
1:1.8.0.5.10-1jpp.1.el7
fixed
java-1.8.0-ibm-jdbc
RHEL 6
1:1.8.0.5.10-1jpp.1.el6_9
fixed
RHEL 7
1:1.8.0.5.10-1jpp.1.el7
fixed
java-1.8.0-ibm-plugin
RHEL 6
1:1.8.0.5.10-1jpp.1.el6_9
fixed
RHEL 7
1:1.8.0.5.10-1jpp.1.el7
fixed
java-1.8.0-ibm-src
RHEL 6
1:1.8.0.5.10-1jpp.1.el6_9
fixed
RHEL 7
1:1.8.0.5.10-1jpp.1.el7
fixed