CVE-2018-3169 is a high-severity vulnerability (CVSS 8.3) affecting Oracle Java SE and Java SE Embedded, specifically versions 7u191, 8u182, 11, and 8u181 respectively. This flaw, located in the Hotspot subcomponent, allows an unauthenticated attacker to compromise affected Java deployments through network access. While difficult to exploit and requiring user interaction, successful attacks can lead to a complete takeover of the vulnerable Java environment, potentially impacting additional products. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update191:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update181:*:*:*:*:*:* | ||
11.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:11.0.0:*:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update191:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update181:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.