Unknown
CVE-2018-10237
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2018-10237
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
- google,
- oracle,
- redhat
Products
- banking payments,
- communications ip service activator 7.3.0,
- communications ip service activator 7.4.0,
- customer management and segmentation foundation 18.0,
- database server 12.2.0.1,
- database server 18c,
- database server 19c,
- flexcube investor servicing 12.1.0,
- flexcube investor servicing 12.3.0,
- flexcube investor servicing 12.4.0,
- flexcube investor servicing 14.0.0,
- flexcube investor servicing 14.1.0,
- flexcube private banking 12.0.0,
- flexcube private banking 12.1.0,
- guava,
- jboss enterprise application platform 6.0.0,
- jboss enterprise application platform 6.4.0,
- jboss enterprise application platform 7.1.0,
- openshift container platform 3.11,
- openshift container platform 4.1,
- openstack 13,
- retail integration bus 15.0,
- retail integration bus 16.0,
- retail xstore point of service 15.0,
- retail xstore point of service 16.0,
- retail xstore point of service 17.0,
- retail xstore point of service 7.1,
- satellite 6.4,
- satellite capsule 6.4,
- virtualization 4.0,
- virtualization 4.2,
- virtualization host 4.0,
- weblogic server 12.2.1.3.0
References
Advisory
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: