RHSA-2018:2712: Moderate: java-1.7.1-ibm security update
IBM Java SE version 7 Release 1 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit.This update upgrades IBM Java SE 7 to version 7R1 SR4-FP30.Security Fix(es): IBM JDK: privilege escalation via insufficiently restricted access to Attach API (CVE-2018-12539) IBM JDK: DoS in the java.math component (CVE-2018-1517) IBM JDK: path traversal flaw in the Diagnostic Tooling Framework (CVE-2018-1656) Oracle JDK: unspecified vulnerability fixed in 6u201, 7u191, 8u181, and 10.0.2 (Libraries) (CVE-2018-2940) OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547) (CVE-2018-2952) Oracle JDK: unspecified vulnerability fixed in 6u201, 7u191, 8u181, and 10.0.2 (JSSE) (CVE-2018-2973) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10
Event History
Frequently Asked Questions
What is the severity of RHSA-2018:2712?
RHSA-2018:2712 is classified as a security vulnerability that allows for privilege escalation due to insufficiently restricted access.
How do I fix RHSA-2018:2712?
To fix RHSA-2018:2712, upgrade to IBM Java SE version 7R1 SR4-FP30 or later.
What software packages are affected by RHSA-2018:2712?
RHSA-2018:2712 affects the IBM Java SE version 7 packages including java and java-devel for specific versions.
Is a reboot required after applying the fix for RHSA-2018:2712?
Yes, a reboot may be required to fully apply the security updates related to RHSA-2018:2712.
What is the main risk associated with RHSA-2018:2712?
The main risk associated with RHSA-2018:2712 is the potential for attackers to escalate privileges within the affected software environment.