CVE-2018-2602 is a difficult-to-exploit vulnerability within the I18n subcomponent of Oracle Java SE and Java SE Embedded, affecting versions 6u171, 7u161, 8u152, 9.0.1, and 8u151 respectively. This vulnerability primarily impacts client-side Java deployments running untrusted code, such as sandboxed Java Web Start applications or applets. Successful exploitation requires unauthenticated access to the infrastructure where Java executes and human interaction, leading to limited unauthorized data modification, read access, and partial denial of service. With a CVSS v3.0 base score of 4.5 (Medium), its attack vector is local, but attack complexity is high, and user interaction is required. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.6.0:update171:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update161:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update152:*:*:*:*:*:* | ||
9.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:9.0.1:*:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.6.0:update171:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.