Security restrictions bypass in IBM Java SDK - CVE-2018-1417
Published: May 2, 2018
Vulnerability identifier: #VU12354
CSH Severity: Low
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1417
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain elevated privileges on the target system.
The weakness exists due to allowing untrusted code running under a security manager. A remote attacker can gain root privileges.
The weakness exists due to allowing untrusted code running under a security manager. A remote attacker can gain root privileges.
Affected software
IBM Java SDK
IBM AIX
Red Hat Satellite
IBM Cognos Command Center
IBM AIX
Red Hat Satellite
IBM Cognos Command Center
How to mitigate CVE-2018-1417
Install update from vendor's website.