CVE-2018-2794: High severity Oracle JDK vulnerability
It was discovered that the Security component of OpenJDK did not restrict which classes could be used when deserializing keys form the JCEKS key stores. A specially crafted JCEKS key store could possibly use this flaw to execute arbitrary code with the privileges of an application reading data form the key store.
The fix adds support for a new security property jceks.key.serialFilter which can be used to specify classes that can be used when deserializing data from the JCEKS key stores.
Other sources
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162, 10 and JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, JRockit executes to compromise Java SE, JRockit. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, JRockit. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-2794?
CVE-2018-2794 is a vulnerability in the Java SE JRockit component of Oracle Java SE (subcomponent: Security).
Which versions of Java SE are affected by CVE-2018-2794?
Java SE: 6u181, 7u171, 8u162, 10
How severe is CVE-2018-2794?
CVE-2018-2794 has a severity rating of 7.7 (high).
How can I fix CVE-2018-2794?
To fix CVE-2018-2794, update to the following versions: openjdk-8u382-ga-2, Oracle JDK 1.6.0-update181, 1.7.0-update171, 1.8.0-update162, 1.10.0, or Oracle JRockit r28.3.17.
Where can I find more information about CVE-2018-2794?
You can find more information about CVE-2018-2794 on the Oracle Security Advisory and SecurityFocus websites.