

Rewterz Threat Advisory – Ryuk evolves as a new Targeted Ransomware
December 20, 2018
Rewterz Threat Advisory – CVE-2018-15465 – Cisco Adaptive Security Appliance Software Privilege Escalation Vulnerability
December 24, 2018
Rewterz Threat Advisory – Ryuk evolves as a new Targeted Ransomware
December 20, 2018
Rewterz Threat Advisory – CVE-2018-15465 – Cisco Adaptive Security Appliance Software Privilege Escalation Vulnerability
December 24, 2018SEVERITY: Medium
CATEGORY: Vulnerability
ANALYSIS SUMMARY
This vulnerability has previously been reported and is now being updated. Oracle Java SE, Java SE Embedded and JRockit are prone to a remote security vulnerability, which can be exploited over multiple protocols. This issue affects the ‘JNDI’ component. This vulnerability affects the following supported versions: Java SE: 6u201, 7u191, 8u182, 11; Java SE Embedded: 8u181; JRockit: R28.3.19. The vulnerability does not require authentication to be exploited. However, It is hard to exploit and several special conditions must be satisfied to exploit it.
This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g. code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g. through a web service which supplies data to the APIs.
IMPACT
Information Disclosure, Data modification, Reduced performance
AFFECTED PRODUCTS
- IBM Vios 2.2.1 4
- IBM Vios 2.2
- IBM Vios 2.2.4.0
- IBM Vios 2.2.3.50
- IBM Vios 2.2.3.4
- IBM Vios 2.2.3.3
- IBM Vios 2.2.3.2
- IBM Vios 2.2.3.0
- IBM Vios 2.2.2.6
- IBM Vios 2.2.2.5
- IBM Vios 2.2.2.4
- IBM Vios 2.2.2.0
- IBM Vios 2.2.1.9
- IBM Vios 2.2.1.8
- IBM Vios 2.2.1.3
- IBM Vios 2.2.1.1
- IBM Vios 2.2.1.0
- IBM Vios 2.2.0.13
- IBM Vios 2.2.0.12
- IBM Vios 2.2.0.11
- IBM Vios 2.2.0.10
- IBM Java 8.0.5.6
- IBM Java 8.0.5.5
- IBM Java 8.0.5.17
- IBM Java 8.0.5.11
- IBM Java 7.1.4.5
- IBM Java 7.1.4.10
- IBM Java 7.1.4.1
- IBM Java 7.1.4.0
- IBM Java 7.0.10.5
- IBM Java 7.0.10.10
- IBM Java 7.0.10.1
- IBM Java 7.0.10.0
- IBM Java 6.1.8.7
- IBM Java 6.1.8.50
- IBM Java 6.1.8.5
- IBM Java 6.1.8.45
- IBM Java 6.1.8.41
- IBM Java 6.1.8.40
- IBM Java 6.1.8.4
- IBM Java 6.1.8.35
- IBM Java 6.1.8.3
- IBM Java 6.1.8.20
- IBM Java 6.1.8.2
- IBM Java 6.1.8.15
- IBM Java 6.1.8.0
- IBM Java 6.0.16.21
- IBM Java 6.0.16.20
- IBM Java 6.0.16.2
- IBM Java 6.0.16.16
- IBM Java 6.0.16.15
- IBM Java 6.0.16.1
- IBM Java 6.0.16.0
- IBM Aix 7.2
- IBM AIX 7.1
- IBM AIX 6.1
- IBM Vios 2.2.3
- Oracle JRockit R28.3.19
- Oracle JRE(Windows Production Release) 1.8 Update 182
- Oracle JRE(Windows Production Release) 1.8 Update 181
- Oracle JRE(Windows Production Release) 1.7 Update 191
- Oracle JRE(Windows Production Release) 1.6 Update 201
- Oracle JRE(Windows Production Release) 11
- Oracle JRE(Solaris Production Release) 1.8 Update 182
- Oracle JRE(Solaris Production Release) 1.8 Update 181
- Oracle JRE(Solaris Production Release) 1.7 Update 191
- Oracle JRE(Solaris Production Release) 1.6 Update 201
- Oracle JRE(Solaris Production Release) 11
- Oracle JRE(macOS Production Release) 1.8 Update 182
- Oracle JRE(macOS Production Release) 1.8 Update 181
- Oracle JRE(macOS Production Release) 1.7 Update 191
- Oracle JRE(macOS Production Release) 1.6 Update 201
- Oracle JRE(macOS Production Release) 11
- Oracle JRE(Linux Production Release) 1.8 Update 182
- Oracle JRE(Linux Production Release) 1.8 Update 181
- Oracle JRE(Linux Production Release) 1.7 Update 191
- Oracle JRE(Linux Production Release) 1.6 Update 201
- Oracle JRE(Linux Production Release) 11
- Oracle JDK(Windows Production Release) 1.8 Update 182
- Oracle JDK(Windows Production Release) 1.8 Update 181
- Oracle JDK(Windows Production Release) 1.7 Update 191
- Oracle JDK(Windows Production Release) 1.6 Update 201
- Oracle JDK(Windows Production Release) 11
- Oracle JDK(Solaris Production Release) 1.8 Update 182
- Oracle JDK(Solaris Production Release) 1.8 Update 181
- Oracle JDK(Solaris Production Release) 1.7 Update 191
- Oracle JDK(Solaris Production Release) 1.6 Update 201
- Oracle JDK(Solaris Production Release) 11
- Oracle JDK(macOS Production Release) 1.8 Update 182
- Oracle JDK(macOS Production Release) 1.8 Update 181
- Oracle JDK(macOS Production Release) 1.7 Update 191
- Oracle JDK(macOS Production Release) 1.6 Update 201
- Oracle JDK(macOS Production Release) 11
- Oracle JDK(Linux Production Release) 1.8 Update 182
- Oracle JDK(Linux Production Release) 1.8 Update 181
- Oracle JDK(Linux Production Release) 1.7 Update 191
- Oracle JDK(Linux Production Release) 1.6 Update 201
- Oracle JDK(Linux Production Release) 11
REMEDIATION
Updates are available. Follow vendor advisory for further details.
http://aix.software.ibm.com/aix/efixes/security/java_oct2018_advisory.asc https://developer.ibm.com/javasdk/support/security-vulnerabilities/#Oracle_October_16_2018_CPU
Or update to a non-vulnerable version. Following products are not affected.
IBM Java 8.0.5.25
IBM Java 7.1.4.35
IBM Java 7.0.10.35
IBM Java 6.1.8.75
IBM Java 6.0.16.75