F5 Networks BIG-IP : Oracle Java SE vulnerability (K44923228)

Medium Nessus Plugin ID 118663

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

Vulnerability in the Java SE, Java SE Embedded, JRockit component of
Oracle Java SE (subcomponent: Security). Supported versions that are
affected are Java SE: 6u181, 7u161 and 8u152; Java SE Embedded: 8u152;
JRockit: R28.3.17. Difficult to exploit vulnerability allows
unauthenticated attacker with network access via multiple protocols to
compromise Java SE, Java SE Embedded, JRockit. Successful attacks of
this vulnerability can result in unauthorized creation, deletion or
modification access to critical data or all Java SE, Java SE Embedded,
JRockit accessible data as well as unauthorized access to critical
data or complete access to all Java SE, Java SE Embedded, JRockit
accessible data. Note: Applies to client and server deployment of
Java. This vulnerability can be exploited through sandboxed Java Web
Start applications and sandboxed Java applets. It can also be
exploited by supplying data to APIs in the specified Component without
using sandboxed Java Web Start applications or sandboxed Java applets,
such as through a web service. CVSS 3.0 Base Score 7.4
(Confidentiality and Integrity impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). (CVE-2018-2783)

Impact

BIG-IP, BIG-IQ, F5 iWorkflow, Enterprise Manager, and Traffix SDC

Attacker with network access via multiple protocols may exploit this
vulnerability with unauthorized access and manipulation to the
affected data of all Java SE components.

LineRate

There is no impact; thisF5 productis not affected by this
vulnerability.

Solution

Upgrade to one of the non-vulnerable versions listed in the F5
Solution K44923228.

See Also

https://support.f5.com/csp/article/K44923228

Plugin Details

Severity: Medium

ID: 118663

File Name: f5_bigip_SOL44923228.nasl

Version: 1.3

Type: local

Published: 2018/11/02

Modified: 2019/01/04

Dependencies: 76940

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 5.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS v3.0

Base Score: 7.4

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Vulnerability Information

CPE: cpe:/a:f5:big-ip_access_policy_manager, cpe:/a:f5:big-ip_advanced_firewall_manager, cpe:/a:f5:big-ip_application_acceleration_manager, cpe:/a:f5:big-ip_application_security_manager, cpe:/a:f5:big-ip_application_visibility_and_reporting, cpe:/a:f5:big-ip_global_traffic_manager, cpe:/a:f5:big-ip_link_controller, cpe:/a:f5:big-ip_local_traffic_manager, cpe:/a:f5:big-ip_policy_enforcement_manager, cpe:/a:f5:big-ip_webaccelerator, cpe:/h:f5:big-ip

Patch Publication Date: 2018/05/10

Reference Information

CVE: CVE-2018-2783