Improper input validation in Oracle Java SE - CVE-2018-3157
Published: August 4, 2020
Vulnerability identifier: #VU33717
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-3157
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The vulnerability exists due to improper input validation within the Sound component in Java SE. A remote non-authenticated attacker can exploit this vulnerability to gain access to sensitive information.
Affected software
Oracle Java SE
Opensuse
EMC Integrated Data Protection Appliance
Opensuse
EMC Integrated Data Protection Appliance
How to mitigate CVE-2018-3157
Install updates from vendor's website.
EMC Integrated Data Protection Appliance - update to 2.3