CVE-2018-2582 is a vulnerability in Oracle Java SE and Java SE Embedded (Hotspot subcomponent) affecting versions 8u152, 9.0.1, and 8u151 respectively. This easily exploitable flaw allows an unauthenticated attacker to compromise the integrity of critical data through network access, requiring user interaction. While the CVSS 3.0 Base Score is 6.5 (Medium), indicating a significant integrity impact, there is no known active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE. This vulnerability can impact both client and server deployments and can be exploited via sandboxed applications or by supplying data to APIs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update152:*:*:*:*:*:* | ||
9.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:9.0.1:*:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update152:*:*:*:*:*:* | ||
9.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:jre:9.0.1:*:*:*:*:*:*:* | ||
5.8CPE matchmatch criteria | cpe:2.3:a:redhat:satellite:5.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.