CVE-2018-2633 is a critical vulnerability in the JNDI subcomponent of Oracle Java SE, Java SE Embedded, and JRockit, affecting versions including Java SE 6u171, 7u161, 8u152, 9.0.1, and Java SE Embedded 8u151. This vulnerability, with a CVSS 3.0 Base Score of 8.3 (High), allows an unauthenticated attacker with network access to achieve complete takeover of the affected Java components. Exploitation is difficult and requires user interaction, but successful attacks can significantly impact additional products beyond Java itself. Despite its severity, there is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.6.0:update171:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update161:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update152:*:*:*:*:*:* | ||
9.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:9.0.1:*:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.6.0:update171:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.