CVE-2018-3139 is a low-severity vulnerability in the Networking subcomponent of Oracle Java SE and Java SE Embedded, affecting versions 6u201, 7u191, 8u182, 11, and 8u181 respectively. This vulnerability allows an unauthenticated attacker with network access to achieve unauthorized read access to a subset of data, but requires human interaction from a victim. The attack complexity is high, and it primarily impacts client-side Java deployments running untrusted code in a sandbox. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.6.0:update201:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update191:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update181:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update182:*:*:*:*:*:* | ||
11.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:11.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.