CVE-2018-1890: Code Injection
Published Mar 11, 2019
·Updated
IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 152081.
Affected Software
1 affected component
IBM SDK=8.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Mar 11, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2018-1890?
CVE-2018-1890 is a vulnerability in IBM SDK Java Technology Edition Version 8 on the AIX platform that allows local users to perform code injection and privilege elevation.
2
What is the severity level of CVE-2018-1890?
CVE-2018-1890 has a severity level of 7.8 (High).
3
How does CVE-2018-1890 affect IBM SDK Java Technology Edition?
CVE-2018-1890 affects IBM SDK Java Technology Edition Version 8 on the AIX platform.
4
How can local users exploit CVE-2018-1890?
Local users can exploit CVE-2018-1890 to perform code injection and privilege elevation.
5
Is there a fix available for CVE-2018-1890?
Yes, IBM has provided a fix for CVE-2018-1890. Please refer to the IBM website for more information.