CVE-2018-2627

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Installer). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to the Windows installer only. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:jdk:1.8.0:update152:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:9.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.8.0:update152:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:9.0.1:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:satellite:5.8:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:e-series_santricity_management_plug-ins:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:e-series_santricity_storage_manager:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:e-series_santricity_web_services:-:*:*:*:*:web_services_proxy:*:*
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:oncommand_shift:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:oncommand_unified_manager:-:*:*:*:*:7-mode:*:*
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:plug-in_for_symantec_netbackup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:santricity_cloud_connector:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:oracle:*:*
cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:sap:*:*
cpe:2.3:a:netapp:storage_replication_adapter_for_clustered_data_ontap:*:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:storage_replication_adapter_for_clustered_data_ontap:*:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap:6.0:*:*:*:*:*:*:*
cpe:2.3:a:netapp:virtual_storage_console:*:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:virtual_storage_console:6.0:*:*:*:*:*:*:*

History

21 Nov 2023, 19:13

Type Values Removed Values Added
CPE cpe:2.3:a:oracle:jdk:1.9.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.9.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:9.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:9.0.1:*:*:*:*:*:*:*
References (SECTRACK) http://www.securitytracker.com/id/1040203 - Broken Link (SECTRACK) http://www.securitytracker.com/id/1040203 - Broken Link, Third Party Advisory, VDB Entry
References (BID) http://www.securityfocus.com/bid/102584 - Broken Link (BID) http://www.securityfocus.com/bid/102584 - Broken Link, Third Party Advisory, VDB Entry

12 Aug 2022, 18:04

Type Values Removed Values Added
First Time Netapp plug-in For Symantec Netbackup
Netapp storage Replication Adapter For Clustered Data Ontap
Netapp e-series Santricity Os Controller
Netapp e-series Santricity Management Plug-ins
Netapp oncommand Shift
Netapp virtual Storage Console
Netapp storagegrid
Netapp santricity Cloud Connector
Netapp
Netapp oncommand Unified Manager
Netapp e-series Santricity Web Services
Netapp snapmanager
Netapp cloud Backup
Redhat
Redhat satellite
Netapp vasa Provider For Clustered Data Ontap
Netapp oncommand Workflow Automation
Netapp oncommand Insight
Netapp e-series Santricity Storage Manager
Netapp active Iq Unified Manager
CPE cpe:2.3:a:netapp:storage_replication_adapter_for_clustered_data_ontap:*:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:e-series_santricity_web_services:-:*:*:*:*:web_services_proxy:*:*
cpe:2.3:a:netapp:santricity_cloud_connector:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:virtual_storage_console:*:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:e-series_santricity_storage_manager:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:virtual_storage_console:6.0:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:e-series_santricity_management_plug-ins:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:plug-in_for_symantec_netbackup:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:5.8:*:*:*:*:*:*:*
cpe:2.3:a:netapp:storage_replication_adapter_for_clustered_data_ontap:*:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:oncommand_unified_manager:-:*:*:*:*:7-mode:*:*
cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap:6.0:*:*:*:*:*:*:*
cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:sap:*:*
cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:oracle:*:*
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:oncommand_shift:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*
References (BID) http://www.securityfocus.com/bid/102584 - Third Party Advisory, VDB Entry (BID) http://www.securityfocus.com/bid/102584 - Broken Link
References (REDHAT) https://access.redhat.com/errata/RHSA-2018:1463 - (REDHAT) https://access.redhat.com/errata/RHSA-2018:1463 - Third Party Advisory
References (CONFIRM) https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0 - (CONFIRM) https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0 - Third Party Advisory
References (SECTRACK) http://www.securitytracker.com/id/1040203 - Third Party Advisory, VDB Entry (SECTRACK) http://www.securitytracker.com/id/1040203 - Broken Link

13 May 2022, 14:57

Type Values Removed Values Added
CPE cpe:2.3:a:oracle:jre:1.8.0:update_152:*:*:*:*:*:* cpe:2.3:a:oracle:jre:1.8.0:update152:*:*:*:*:*:*

Information

Published : 2018-01-18 02:29

Updated : 2023-12-10 12:30


NVD link : CVE-2018-2627

Mitre link : CVE-2018-2627

CVE.ORG link : CVE-2018-2627


JSON object : View

Products Affected

netapp

  • oncommand_workflow_automation
  • cloud_backup
  • oncommand_insight
  • virtual_storage_console
  • storagegrid
  • e-series_santricity_storage_manager
  • active_iq_unified_manager
  • oncommand_unified_manager
  • vasa_provider_for_clustered_data_ontap
  • snapmanager
  • oncommand_shift
  • santricity_cloud_connector
  • e-series_santricity_management_plug-ins
  • plug-in_for_symantec_netbackup
  • storage_replication_adapter_for_clustered_data_ontap
  • e-series_santricity_os_controller
  • e-series_santricity_web_services

oracle

  • jre
  • jdk

redhat

  • satellite