First published: Wed Jan 17 2018(Updated: )
Oracle Java SE 8u161 and 9.0.4 fixes an unspecified vulnerability in the Deployment component (<a href="https://access.redhat.com/security/cve/CVE-2018-2639">CVE-2018-2639</a>). Upstream has CVSS scored this issue as: 8.3/CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H External Reference: <a href="http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html#AppendixJAVA">http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html#AppendixJAVA</a>
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JDK 6 | =1.8.0-update152 | |
Oracle JDK 6 | =9.0.1 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update152 | |
Oracle Java Runtime Environment (JRE) | =9.0.1 | |
redhat satellite | =5.8 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux eus | =7.5 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux workstation | =6.0 | |
redhat enterprise Linux workstation | =7.0 | |
Oracle JDK 6 | =1.9.0.1 | |
Oracle Java Runtime Environment (JRE) | =1.9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2639 has a CVSS score of 8.3, indicating a high severity level.
To fix CVE-2018-2639, upgrade to Oracle Java SE version 8u161 or 9.0.4 or later.
CVE-2018-2639 affects the Deployment component of Oracle Java SE.
Yes, CVE-2018-2639 can be exploited remotely due to its nature.
Oracle JDK 1.8.0 update 152 and 9.0.1, along with their respective JRE versions, are vulnerable to CVE-2018-2639.