Security restrictions bypass in Apache Derby - CVE-2018-1313

 

Security restrictions bypass in Apache Derby - CVE-2018-1313

Published: May 8, 2018 / Updated: May 8, 2018


Vulnerability identifier: #VU12420
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1313
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to bypass security restrictions to the target system.

The weakness exists in the Network Server component due to improper security restrictions. If the Derby Network Server is started without specifying a security manager, the Derby Network Server will install a default Java security manager that enforces a basic policy. A remote attacker can send a specially crafted packet and cause the system to boot a database for which the location and contents of the database are under the attacker's control.

Affected software

Apache Derby
Storage Defender - Resiliency Service
IBM Planning Analytics Workspace
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
IBM Cloud Pak System
openEuler
Log Analysis
Netcool Operations Insight
Tivoli Composite Application Manager for Transactions
Dell Data Lakehouse
Operational Decision Manager
derby
derby-javadoc

How to mitigate CVE-2018-1313

Update to version 10.14.2.0.

Storage Defender - Resiliency Service - update to 2.0.14
IBM Cloud Pak System - update to 2.3.3.6
Log Analysis - update to 1.3.7.2 IF004
Dell Data Lakehouse - update to 1.4.0.0
Netcool Operations Insight - update to 1.6.12
IBM Planning Analytics Workspace - update to 2.0.93
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.22
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10
derby - update to 10.13.1.1-3
derby-javadoc - update to 10.13.1.1-3

External References

Related Security Bulletins