CVE-2018-1517: Input Validation
A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data. IBM X-Force ID: 141681.
Other sources
IBM JDK 8 SR5 FP20 (8.0.5.20), 7 R1 SR4 FP30 (7.1.4.30), 7 SR10 FP30 (7.0.10.30), and 6 SR16 FP70 (6.0.16.70) fix a flaw described by upstream as:
A flaw in the java.math component in IBM SDK, Java Technology Edition may allow an attacker to inflict a denial-of-service attack with specially crafted String data.
References:
https://www-01.ibm.com/support/docview.wss?uid=ibm10719653 https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBMSecurityUpdateAugust2018
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1517?
CVE-2018-1517 has been rated as high severity due to its potential to allow denial-of-service attacks.
How do I fix CVE-2018-1517?
To fix CVE-2018-1517, update to the latest version of the IBM SDK, Java Technology Edition that addresses this vulnerability.
What versions of IBM SDK are affected by CVE-2018-1517?
CVE-2018-1517 affects IBM SDK versions 6.0, 7.0, and 8.0, including their respective service refreshes.
What type of vulnerability is CVE-2018-1517?
CVE-2018-1517 is a denial-of-service vulnerability found in the java.math component of IBM SDK.
Who can be affected by CVE-2018-1517?
Users and applications relying on targeted versions of IBM SDK could be affected by CVE-2018-1517 if exploited.