First published: Tue Oct 16 2018(Updated: )
Oracle Java SE 8u191 fixes an unspecified vulnerability in the JavaFX component (<a href="https://access.redhat.com/security/cve/CVE-2018-3209">CVE-2018-3209</a>). Upstream has CVSS scored this issue as: 8.3/CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H External Reference: <a href="https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html#AppendixJAVA">https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html#AppendixJAVA</a>
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.8.0-oracle-1:1.8.0.191-1jpp.1.el6 | 1.8.0-oracle-1:1.8.0.191-1jpp.1.el6 |
redhat/java | <1.8.0-oracle-1:1.8.0.191-1jpp.1.el7 | 1.8.0-oracle-1:1.8.0.191-1jpp.1.el7 |
Oracle JDK 6 | =1.8.0-update181 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update181 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3209 has a CVSS score of 8.3, indicating it is a high severity vulnerability.
CVE-2018-3209 can lead to critical information disclosure and potential remote exploitation.
CVE-2018-3209 affects Oracle Java SE versions prior to 1.8.0_u191.
To fix CVE-2018-3209, update Oracle Java SE to version 1.8.0_191 or later.
Yes, CVE-2018-3209 specifically targets vulnerabilities in the JavaFX component of Oracle Java.