Uncontrolled memory allocation in Guava: Google Core Libraries For Java - CVE-2018-10237
Published: May 21, 2018 / Updated: May 23, 2018
Vulnerability identifier: #VU12886
CSH Severity: Low
CVSS v4 BT: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2018-10237
CWE-ID: CWE-789
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to unbounded memory allocation. A remote attacker can cause the service to crash and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.
The weakness exists due to unbounded memory allocation. A remote attacker can cause the service to crash and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.
Affected software
Guava: Google Core Libraries For Java
IBM Business Automation Workflow
IBM Integration Bus
IBM PureData System for Operational Analytics
IBM Process Mining
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
Red Hat OpenStack for IBM Power
Red Hat OpenStack
IBM Observability with Instana
Financial Transaction Manager for ACH Services and Check Services
IBM Cloud Application Performance Management (APM)
IBM Spectrum Protect Storage Agent
IBM Security Verify Governance
IBM Spectrum Protect Plus
IBM Tivoli Application Dependency Discovery Manager
Cloudera Data Platform Private Cloud Base for IBM
Apache Pulsar
Voice Gateway
Red Hat OpenShift Container Platform
DataStage on Cloud Pak for Data
IBM OpenPages with Watson
Oracle Retail Xstore Point of Service
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
User Entity Behavior Analytics
Synthetic Playback Agent
Storage Virtualize
Maximo Application Suite - IoT Component
IBM Sterling Order Management
JBoss Enterprise Application Platform
Oracle WebLogic Server
Splunk Enterprise
IBM Security Guardium
Fedora
watsonx.data
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
IBM Case Manager
RSA Authentication Manager
Operational Decision Manager
IBM App Connect Enterprise
IBM InfoSphere Information Server
guava
guava20
IBM Business Automation Workflow
IBM Integration Bus
IBM PureData System for Operational Analytics
IBM Process Mining
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
Red Hat OpenStack for IBM Power
Red Hat OpenStack
IBM Observability with Instana
Financial Transaction Manager for ACH Services and Check Services
IBM Cloud Application Performance Management (APM)
IBM Spectrum Protect Storage Agent
IBM Security Verify Governance
IBM Spectrum Protect Plus
IBM Tivoli Application Dependency Discovery Manager
Cloudera Data Platform Private Cloud Base for IBM
Apache Pulsar
Voice Gateway
Red Hat OpenShift Container Platform
DataStage on Cloud Pak for Data
IBM OpenPages with Watson
Oracle Retail Xstore Point of Service
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
User Entity Behavior Analytics
Synthetic Playback Agent
Storage Virtualize
Maximo Application Suite - IoT Component
IBM Sterling Order Management
JBoss Enterprise Application Platform
Oracle WebLogic Server
Splunk Enterprise
IBM Security Guardium
Fedora
watsonx.data
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
IBM Case Manager
RSA Authentication Manager
Operational Decision Manager
IBM App Connect Enterprise
IBM InfoSphere Information Server
guava
guava20
How to mitigate CVE-2018-10237
Update to version 24.1.1.
Apache Pulsar - update to 2.8.0
IBM Process Mining - update to 2.1.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.8
DataStage on Cloud Pak for Data - update to 4.8.5
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
IBM OpenPages with Watson - update to 8.2.0.1
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.0.9, 9.1.1, 9.1.4, 9.2.1
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
IBM Observability with Instana - update to 1.0.295
watsonx.data - update to 2.0.3
Financial Transaction Manager for ACH Services and Check Services - update to 3.0.5.4 iFix 28
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.5
EMC ViPR SRM - update to 4.10.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
User Entity Behavior Analytics - update to 5.0.2
IBM Case Manager - update to 5.3.3-IF011
Synthetic Playback Agent - update to 8.1.4 IF18
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Spectrum Protect Storage Agent - update to 8.1.19
RSA Authentication Manager - update to 8.5 Patch 3
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
Maximo Application Suite - IoT Component - addressed in versions 8.7.15, 8.8.11, 9.0.1
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
IBM Sterling Order Management - update to 10.0.0.29
IBM Security Verify Governance - update to 10.0.1.0.4
IBM Spectrum Protect Plus - update to 10.1.14
IBM App Connect Enterprise - addressed in versions 11.0.0.21, 12.0.9.0
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
guava - addressed in versions 18.0-12.fc26, 18.0-12.fc27, 24.0-3.fc28
guava20 - update to 20.0-6.fc28
IBM Process Mining - update to 2.1.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.8
DataStage on Cloud Pak for Data - update to 4.8.5
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
IBM OpenPages with Watson - update to 8.2.0.1
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.0.9, 9.1.1, 9.1.4, 9.2.1
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
IBM Observability with Instana - update to 1.0.295
watsonx.data - update to 2.0.3
Financial Transaction Manager for ACH Services and Check Services - update to 3.0.5.4 iFix 28
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.5
EMC ViPR SRM - update to 4.10.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
User Entity Behavior Analytics - update to 5.0.2
IBM Case Manager - update to 5.3.3-IF011
Synthetic Playback Agent - update to 8.1.4 IF18
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Spectrum Protect Storage Agent - update to 8.1.19
RSA Authentication Manager - update to 8.5 Patch 3
Storage Virtualize - addressed in versions 8.6.3.0, 8.7.0.0
Maximo Application Suite - IoT Component - addressed in versions 8.7.15, 8.8.11, 9.0.1
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
IBM Sterling Order Management - update to 10.0.0.29
IBM Security Verify Governance - update to 10.0.1.0.4
IBM Spectrum Protect Plus - update to 10.1.14
IBM App Connect Enterprise - addressed in versions 11.0.0.21, 12.0.9.0
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
guava - addressed in versions 18.0-12.fc26, 18.0-12.fc27, 24.0-3.fc28
guava20 - update to 20.0-6.fc28
External References
Related Security Bulletins
- Denial of service in Google Guava
- Red Hat update for Google Guava
- Red Hat update for Red Hat JBoss Enterprise Application Platform 6.4.21
- Red Hat update for Red Hat JBoss Enterprise Application Platform 6.4.21
- Red Hat update for Red Hat JBoss Enterprise Application Platform 6.4.21
- Red Hat update for OpenShift Container Platform 4.1.18 logging-elasticsearch5
- Red Hat update for OpenShift Container Platform logging-elasticsearch5-container
- Multiple vulnerabilities in Oracle Retail Xstore Point of Service
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in Apache Pulsar
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in IBM PureData System for Operational Analytics
- Multiple vulnerabilities in IBM Security Guardium
- Uncontrolled memory allocation in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Voice Gateway
- Uncontrolled memory allocation in IBM Sterling Order Management
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in APM Synthetic Playback Agent
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in IBM App Connect Enterprise and IBM Integration Bus
- Uncontrolled memory allocation in IBM OpenPages with Watson
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Application Performance Management products
- Uncontrolled memory allocation in IBM Tivoli Application Dependency Discovery Manager
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM Business Automation Workflow and IBM Case Manager
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Splunk Enterprise update for third-party components
- Multiple vulnerabilities in IBM Storage Virtualize
- IBM watsonx.data update for Google Guava
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Fedora 26 update for guava
- Fedora 27 update for guava
- Fedora 28 update for guava
- Fedora 28 update for guava20
- RSA Authentication Manager update for third-party components
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in Cloudera Data Platform Private Cloud Base with IBM (CDP)
- Multiple vulnerabilities in IBM User Entity Behavior Analytics
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager Essentials Edition
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in IBM Financial Transaction Manager for ACH Services and Check Services for Multi-Platform