CVE-2018-1417: High severity ibm sdk vulnerability
Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code running under a security manager to elevate its privileges.
External References:
https://exchange.xforce.ibmcloud.com/vulnerabilities/138823
Other sources
Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code running under a security manager to elevate its privileges. IBM X-Force ID: 138823.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1417?
CVE-2018-1417 has a moderate severity rating due to the potential for privilege escalation in the J9 JVM.
How do I fix CVE-2018-1417?
To fix CVE-2018-1417, update the IBM SDK for Java Technology Edition to versions that are not affected.
What systems are affected by CVE-2018-1417?
CVE-2018-1417 affects IBM SDK, Java Technology Edition versions 6.0.0.0, 6.1.0.0, 7.0.0.0, 7.1.0.0, and 8.0.0.0.
What kind of threat does CVE-2018-1417 pose?
CVE-2018-1417 poses a threat by allowing untrusted code to elevate its privileges under a security manager.
Is there a workaround for CVE-2018-1417?
There are no specific workarounds for CVE-2018-1417; the recommended action is to upgrade to a secure version.