First published: Wed Apr 18 2018(Updated: )
Oracle Java SE 8u171 and 10.0.1 fixes an unspecified vulnerability in the Install component (<a href="https://access.redhat.com/security/cve/CVE-2018-2811">CVE-2018-2811</a>). Upstream has CVSS scored this issue as: 7.7/CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H External Reference: <a href="http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html#AppendixJAVA">http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html#AppendixJAVA</a>
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JDK | =1.8.0-update162 | |
Oracle JDK | =1.10.0 | |
Oracle JRE | =1.8.0-update162 | |
Oracle JRE | =1.10.0 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Workstation | =6.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
Schneider-electric Struxureware Data Center Expert | <7.6.0 | |
Oracle JDK | =10 | |
Oracle JRE | =10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2811 is a vulnerability in the Java SE component of Oracle Java SE that affects versions 8u162 and 10.
CVE-2018-2811 has a severity rating of 7.7 (high).
CVE-2018-2811 affects Oracle JDK version 1.8.0-update162 and 1.10.0.
CVE-2018-2811 affects Oracle JRE version 1.8.0-update162 and 1.10.0.
CVE-2018-2811 affects Redhat Enterprise Linux Server version 6.0 and 7.0.
CVE-2018-2811 affects Redhat Enterprise Linux Workstation version 6.0 and 7.0.
CVE-2018-2811 affects Schneider-electric Struxureware Data Center Expert up to version 7.6.0.
More information about CVE-2018-2811 can be found on the Oracle website and security advisory links provided: [Oracle website](http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html), [SecurityFocus](http://www.securityfocus.com/bid/103810), [SecurityTracker](http://www.securitytracker.com/id/1040697).