Security restrictions bypass in Apache Derby - CVE-2018-1313
Published: May 8, 2018 / Updated: May 8, 2018
Vulnerability identifier: #VU12420
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1313
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to bypass security restrictions to the target system.
The weakness exists in the Network Server component due to improper security restrictions. If the Derby Network Server is started without specifying a security manager, the Derby Network Server will install a default Java security manager that enforces a basic policy. A remote attacker can send a specially crafted packet and cause the system to boot a database for which the location and contents of the database are under the attacker's control.
The weakness exists in the Network Server component due to improper security restrictions. If the Derby Network Server is started without specifying a security manager, the Derby Network Server will install a default Java security manager that enforces a basic policy. A remote attacker can send a specially crafted packet and cause the system to boot a database for which the location and contents of the database are under the attacker's control.
Affected software
Apache Derby
Storage Defender - Resiliency Service
IBM Planning Analytics Workspace
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
IBM Cloud Pak System
openEuler
Log Analysis
Netcool Operations Insight
Tivoli Composite Application Manager for Transactions
Dell Data Lakehouse
Operational Decision Manager
derby
derby-javadoc
Storage Defender - Resiliency Service
IBM Planning Analytics Workspace
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
IBM Cloud Pak System
openEuler
Log Analysis
Netcool Operations Insight
Tivoli Composite Application Manager for Transactions
Dell Data Lakehouse
Operational Decision Manager
derby
derby-javadoc
How to mitigate CVE-2018-1313
Update to version 10.14.2.0.
Storage Defender - Resiliency Service - update to 2.0.14
IBM Cloud Pak System - update to 2.3.3.6
Log Analysis - update to 1.3.7.2 IF004
Dell Data Lakehouse - update to 1.4.0.0
Netcool Operations Insight - update to 1.6.12
IBM Planning Analytics Workspace - update to 2.0.93
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.22
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10
derby - update to 10.13.1.1-3
derby-javadoc - update to 10.13.1.1-3
IBM Cloud Pak System - update to 2.3.3.6
Log Analysis - update to 1.3.7.2 IF004
Dell Data Lakehouse - update to 1.4.0.0
Netcool Operations Insight - update to 1.6.12
IBM Planning Analytics Workspace - update to 2.0.93
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.22
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10
derby - update to 10.13.1.1-3
derby-javadoc - update to 10.13.1.1-3
External References
Related Security Bulletins
- Security restrictions bypass in Apache Derby
- Security restrictions bypass in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in IBM Cloud Pak System
- Security restrictions bypass in ITCAM for Transactions
- openEuler 20.03 LTS SP1 update for derby
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Planning Analytics Workspace
- Multiple vulnerabilities in IBM Operational Decision Manager
- Dell Data Lakehouse update for third-party components
- Multiple vulnerabilities in IBM Storage Defender - Resiliency Service