REDHAT-BUG-1618869: Path Traversal
IBM JDK 8 SR5 FP20 (8.0.5.20), 7 R1 SR4 FP30 (7.1.4.30), 7 SR10 FP30 (7.0.10.30), and 6 SR16 FP70 (6.0.16.70) fix a flaw described by upstream as:
The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) does not protect against path traversal attacks when extracting compressed dump files.
References:
https://www-01.ibm.com/support/docview.wss?uid=ibm10719653 https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBMSecurityUpdateAugust2018
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1618869?
The severity of REDHAT-BUG-1618869 is classified as important due to the potential for path traversal attacks.
How do I fix REDHAT-BUG-1618869?
To fix REDHAT-BUG-1618869, update to the patched versions of the IBM JDK provided in the release notes.
What products are affected by REDHAT-BUG-1618869?
REDHAT-BUG-1618869 affects IBM JDK 8 SR5 FP20, IBM JDK 7 R1 SR4 FP30, IBM JDK 7 SR10 FP30, and IBM JDK 6 SR16 FP70.
What type of attack is described in REDHAT-BUG-1618869?
REDHAT-BUG-1618869 describes a vulnerability that can be exploited through path traversal attacks.
When was REDHAT-BUG-1618869 publicly announced?
REDHAT-BUG-1618869 was publicly announced in August 2018 as a security vulnerability.