First published: Tue Oct 16 2018(Updated: )
Oracle Java SE 8u191 and 11.0.1 fixes an unspecified vulnerability in the Serviceability component (<a href="https://access.redhat.com/security/cve/CVE-2018-3211">CVE-2018-3211</a>). Upstream has CVSS scored this issue as: 6.6/CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N External Reference: <a href="https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html#AppendixJAVA">https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html#AppendixJAVA</a>
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.8.0-oracle-1:1.8.0.191-1jpp.1.el6 | 1.8.0-oracle-1:1.8.0.191-1jpp.1.el6 |
redhat/java | <1.8.0-oracle-1:1.8.0.191-1jpp.1.el7 | 1.8.0-oracle-1:1.8.0.191-1jpp.1.el7 |
Oracle JDK 6 | =1.8.0-update181 | |
Oracle JDK 6 | =11.0.0 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update181 | |
Oracle Java Runtime Environment (JRE) | =11.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3211 has a CVSS score of 6.6, indicating a medium severity vulnerability.
To fix CVE-2018-3211, upgrade to Oracle Java SE versions 8u191 or 11.0.1 or later.
CVE-2018-3211 affects the Serviceability component of Oracle Java SE.
Yes, CVE-2018-3211 is rated as having an attack vector of local, but it may involve user interaction.
The impacts of CVE-2018-3211 include potential unauthorized information disclosure and modification.