CVE-2018-2599: Medium severity oracle java se 7 vulnerability
It was discovered that the DNS client implementation in the JNDI component of OpenJDK did not use random source ports when sending out DNS queries. This would make it easier for a remote attacker to spoof responses to those queries.
Other sources
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 4.8 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L).
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2599?
The severity of CVE-2018-2599 is medium.
What software versions are affected by CVE-2018-2599?
The affected software versions of CVE-2018-2599 are: Java SE: 6u171, 7u161, 8u152, and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16.
How can an unauthenticated attacker exploit CVE-2018-2599?
An unauthenticated attacker can exploit CVE-2018-2599 through a difficult to exploit vulnerability.
What is the fix for CVE-2018-2599?
The fix for CVE-2018-2599 depends on the software version and can be found in the provided references.
Where can I find more information about CVE-2018-2599?
More information about CVE-2018-2599 can be found in the provided references.