CVE-2018-1656

The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files. IBM X-Force ID: 144882.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
ibmsdk
6.0
ibmsdk
7.0
ibmsdk
8.0
redhatsatellite
5.6
redhatsatellite
5.7
redhatsatellite
5.8
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
oracleenterprise_manager_base_platform
13.2.0.0.0
oracleenterprise_manager_base_platform
13.3.0.0.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ibm-java80
bionic
Fixed 8.0.5.22-0ubuntu1
released
cosmic
dne
trusty
dne
xenial
Fixed 8.0.5.22-0ubuntu1
released
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
java-1.7.1-ibm
RHEL 6
1:1.7.1.4.30-1jpp.2.el6_10
fixed
RHEL 7
1:1.7.1.4.30-1jpp.1.el7
fixed
java-1.7.1-ibm-demo
RHEL 6
1:1.7.1.4.30-1jpp.2.el6_10
fixed
RHEL 7
1:1.7.1.4.30-1jpp.1.el7
fixed
java-1.7.1-ibm-devel
RHEL 6
1:1.7.1.4.30-1jpp.2.el6_10
fixed
RHEL 7
1:1.7.1.4.30-1jpp.1.el7
fixed
java-1.7.1-ibm-jdbc
RHEL 6
1:1.7.1.4.30-1jpp.2.el6_10
fixed
RHEL 7
1:1.7.1.4.30-1jpp.1.el7
fixed
java-1.7.1-ibm-plugin
RHEL 6
1:1.7.1.4.30-1jpp.2.el6_10
fixed
RHEL 7
1:1.7.1.4.30-1jpp.1.el7
fixed
java-1.7.1-ibm-src
RHEL 6
1:1.7.1.4.30-1jpp.2.el6_10
fixed
RHEL 7
1:1.7.1.4.30-1jpp.1.el7
fixed
java-1.8.0-ibm
RHEL 6
1:1.8.0.5.20-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.5.20-1jpp.1.el7
fixed
java-1.8.0-ibm-demo
RHEL 6
1:1.8.0.5.20-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.5.20-1jpp.1.el7
fixed
java-1.8.0-ibm-devel
RHEL 6
1:1.8.0.5.20-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.5.20-1jpp.1.el7
fixed
java-1.8.0-ibm-jdbc
RHEL 6
1:1.8.0.5.20-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.5.20-1jpp.1.el7
fixed
java-1.8.0-ibm-plugin
RHEL 6
1:1.8.0.5.20-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.5.20-1jpp.1.el7
fixed
java-1.8.0-ibm-src
RHEL 6
1:1.8.0.5.20-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.5.20-1jpp.1.el7
fixed