Synopsis
The remote Unix host contains a programming platform that is affected by multiple vulnerabilities.
Description
The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is prior to 11 Update 1, 8 Update 191, 7 Update 201, or 6 Update 211. It is, therefore, affected by multiple vulnerabilities :
  - An unspecified vulnerability in the Java SE Embedded     component of Oracle Java SE in the Deployment (libpng)     subcomponent could allow an unauthenticated, remote     attacker with network access via HTTP to compromise     Java SE. (CVE-2018-13785)  
  - An unspecified vulnerability in the Java SE Embedded     component of Oracle Java SE in the Hotspot subcomponent     that could allow an unauthenticated, remote attacker     with network access via multiple protocols to compromise     Java SE (CVE-2018-3169)
  - An unspecified vulnerability in the Java SE component of     Oracle Java SE in the JavaFX subcomponent could allow an     unauthenticated, remote attacker with network access via     multiple protocols to compromise Java SE.
    (CVE-2018-3209)
  - An unspecified vulnerability in the Java SE, Java SE     Embedded, and JRockit component of Oracle Java SE in     the JNDI subcomponent could allow an unauthenticated,     remote attacker with network access via multiple     protocols to compromise Java SE, Java SE Embedded, and     JRockit. (CVE-2018-3149)     
  - An unspecified vulnerability in the Java SE, Java SE     Embedded, JRockit component of Oracle Java SE in the     JSSE subcomponent could allow an unauthenticated,     remote attacker with network access via SSL/TLS to     compromise Java SE, Java SE Embedded, or JRockit.
    (CVE-2018-3180)
  - An unspecified vulnerability in the Java SE, Java SE     Embedded component of Oracle Java SE in the Networking     subcomponent could allow an unauthenticated, remote     attacker with network access via multiple protocols to     compromise Java SE or Java SE Embedded. (CVE-2018-3139)
  - An unspecified vulnerability in the Java SE, Java SE     Embedded, JRockit component of Oracle Java SE in the     Scripting subcomponent could allow an unauthenticated,     remote attacker with network access via multiple     protocols to compromise Java SE, Java SE Embedded, or     JRockit. (CVE-2018-3183)
  - An unspecified vulnerability in the Java SE, Java SE     Embedded component of Oracle Java SE in the Security     subcomponent could allow an unauthenticated, remote     attacker with network access via multiple protocols to     compromise Java SE, Java SE Embedded. (CVE-2018-3136)
  - An unspecified vulnerability in the Java SE, Java SE     Embedded component of Oracle Java SE in the     Serviceability subcomponent could allow a low privileged     attacker with logon to the infrastructure where Java SE,     Java SE Embedded executes to compromise Java SE, Java SE     Embedded. (CVE-2018-3211)
  - An unspecified vulnerability in the Java SE component of     Oracle Java SE in the Sound subcomponent could allow an     unauthenticated, remote attacker with network access via     multiple protocols to compromise Java SE.
    (CVE-2018-3157)
  - An unspecified vulnerability in the Java SE component of     Oracle Java SE in the Utility subcomponent could allow an     unauthenticated, remote attacker with network access via     multiple protocols to compromise Java SE.
    (CVE-2018-3150)
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Upgrade to Oracle JDK / JRE 11 Update 1, 8 Update 191 / 7 Update 201 / 6 Update 211 or later. If necessary, remove any affected versions.
Note that an Extended Support contract with Oracle is needed to obtain JDK / JRE 6 Update 95 or later.
Plugin Details
File Name: oracle_java_cpu_oct_2018_unix.nasl
Agent: unix
Configuration: Enable thorough checks (optional)
Supported Sensors: Nessus Agent, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
CPE: cpe:/a:oracle:jdk, cpe:/a:oracle:jre
Required KB Items: installed_sw/Java
Exploit Ease: No known exploits are available
Patch Publication Date: 10/16/2018
Vulnerability Publication Date: 10/16/2018
Reference Information
CVE: CVE-2018-13785, CVE-2018-3136, CVE-2018-3139, CVE-2018-3149, CVE-2018-3150, CVE-2018-3157, CVE-2018-3169, CVE-2018-3180, CVE-2018-3183, CVE-2018-3209, CVE-2018-3211, CVE-2018-3214
BID: 105587, 105590, 105591, 105595, 105597, 105599, 105601, 105602, 105608, 105615, 105617, 105622