First published: Wed Jan 17 2018(Updated: )
Oracle Java SE 8u161 and 9.0.4 fixes an unspecified vulnerability in the Installer component (<a href="https://access.redhat.com/security/cve/CVE-2018-2627">CVE-2018-2627</a>). Upstream has CVSS scored this issue as: 7.5/CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H External Reference: <a href="http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html#AppendixJAVA">http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html#AppendixJAVA</a>
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JDK | =1.8.0-update152 | |
Oracle JDK | =1.9.0.1 | |
Oracle JRE | =1.8.0-update152 | |
Oracle JRE | =1.9.0.1 | |
Redhat Satellite | =5.8 | |
Netapp Active Iq Unified Manager Windows | >=7.3 | |
Netapp Active Iq Unified Manager Vmware Vsphere | >=9.5 | |
Netapp Cloud Backup | ||
Netapp E-series Santricity Management Plug-ins | ||
NetApp E-Series SANtricity OS Controller | >=11.0<=11.70.1 | |
Netapp E-series Santricity Storage Manager | ||
Netapp E-series Santricity Web Services Web Services Proxy | ||
NetApp OnCommand Insight | ||
Netapp Oncommand Shift | ||
Netapp Oncommand Unified Manager 7-mode | ||
NetApp OnCommand Workflow Automation | ||
Netapp Plug-in For Symantec Netbackup | ||
Netapp Santricity Cloud Connector | ||
Netapp Snapmanager Oracle | ||
Netapp Snapmanager Sap | ||
Netapp Storage Replication Adapter For Clustered Data Ontap Vmware Vsphere | >=7.2 | |
Netapp Storage Replication Adapter For Clustered Data Ontap Windows | >=7.2 | |
Netapp Storagegrid | <=9.0.4 | |
Netapp Vasa Provider For Clustered Data Ontap | >=7.2 | |
Netapp Vasa Provider For Clustered Data Ontap | =6.0 | |
Netapp Virtual Storage Console Vmware Vsphere | >=7.2 | |
Netapp Virtual Storage Console | =6.0 | |
Oracle JDK | =9.0.1 | |
Oracle JRE | =9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2627 is a vulnerability in the Java SE component of Oracle Java SE, specifically in the Installer subcomponent.
Java SE versions 8u152 and 9.0.1 are affected by CVE-2018-2627.
CVE-2018-2627 has a severity level of 7.5 (high).
An attacker with low privileges and access to the infrastructure where Java SE executes can exploit CVE-2018-2627.
Yes, you can find references for CVE-2018-2627 at the following links: [Oracle Security Advisory](http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html), [SecurityFocus](http://www.securityfocus.com/bid/102584), [SecurityTracker](http://www.securitytracker.com/id/1040203).