First published: Tue Jul 17 2018(Updated: )
Oracle Java SE 7u191, 8u181, and 10.0.2 fixes an unspecified vulnerability in the JavaFX component (<a href="https://access.redhat.com/security/cve/CVE-2018-2941">CVE-2018-2941</a>). Upstream has CVSS scored this issue as: 8.3/CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H External Reference: <a href="http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html#AppendixJAVA">http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html#AppendixJAVA</a>
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.7.0-oracle-1:1.7.0.191-1jpp.1.el6 | 1.7.0-oracle-1:1.7.0.191-1jpp.1.el6 |
redhat/java | <1.8.0-oracle-1:1.8.0.181-1jpp.2.el6 | 1.8.0-oracle-1:1.8.0.181-1jpp.2.el6 |
redhat/java | <1.8.0-oracle-1:1.8.0.181-1jpp.2.el7 | 1.8.0-oracle-1:1.8.0.181-1jpp.2.el7 |
redhat/java | <1.7.0-oracle-1:1.7.0.191-1jpp.2.el7 | 1.7.0-oracle-1:1.7.0.191-1jpp.2.el7 |
Oracle JDK | =1.7.0-update181 | |
Oracle JDK | =1.8.0-update172 | |
Oracle JDK | =10.0.1 | |
Oracle JRE | =1.7.0-update181 | |
Oracle JRE | =1.8.0-update172 | |
Oracle JRE | =10.0.1 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Active Iq Unified Manager Windows | ||
Netapp Cloud Backup | ||
NetApp E-Series SANtricity OS Controller | >=11.0<=11.70.1 | |
Netapp E-series Santricity Storage Manager | ||
NetApp OnCommand Insight | ||
Netapp Oncommand Unified Manager | ||
NetApp OnCommand Workflow Automation | ||
Netapp Plug-in For Symantec Netbackup | ||
Netapp Snapmanager Oracle | ||
Netapp Snapmanager Sap | ||
Netapp Steelstore Cloud Integrated Storage | ||
Netapp Storage Replication Adapter For Clustered Data Ontap Vmware Vsphere | >=9.7 | |
Netapp Vasa Provider For Clustered Data Ontap | >=9.7 | |
Netapp Virtual Storage Console Vmware Vsphere | >=9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2018-2941 is a vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX).
The affected versions of Java SE are 7u181, 8u172, and 10.0.1.
CVE-2018-2941 has a severity score of 8.3, which is considered critical.
An unauthenticated attacker with network access via multiple protocols can exploit this vulnerability to compromise Java SE.
You can find more information about CVE-2018-2941 at the following references: [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2018:2254), [Oracle Security Advisory](http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html#AppendixJAVA).