CVE-2018-2796 is a vulnerability in the Concurrency subcomponent of Oracle Java SE, Java SE Embedded, and JRockit, affecting versions 7u171, 8u162, 10, 8u161, and R28.3.17 respectively. This easily exploitable vulnerability allows unauthenticated attackers with network access to cause a partial denial of service. With a CVSS 3.0 Base Score of 5.3 (Medium), it primarily impacts availability and can be exploited via multiple protocols, including sandboxed Java Web Start applications, applets, or by supplying data to APIs. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update171:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update162:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:10:*:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update171:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update162:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.