Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Network
0

CVE-2018-10237

Disclosure Date: April 26, 2018
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
5.9 Medium
Impact Score:
3.6
Exploitability Score:
2.2
Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector (AV):
Network
Attack Complexity (AC):
High
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
None
Integrity (I):
None
Availability (A):
High

General Information

Vendors

  • google,
  • oracle,
  • redhat

Products

  • banking payments,
  • communications ip service activator 7.3.0,
  • communications ip service activator 7.4.0,
  • customer management and segmentation foundation 18.0,
  • database server 12.2.0.1,
  • database server 18c,
  • database server 19c,
  • flexcube investor servicing 12.1.0,
  • flexcube investor servicing 12.3.0,
  • flexcube investor servicing 12.4.0,
  • flexcube investor servicing 14.0.0,
  • flexcube investor servicing 14.1.0,
  • flexcube private banking 12.0.0,
  • flexcube private banking 12.1.0,
  • guava,
  • jboss enterprise application platform 6.0.0,
  • jboss enterprise application platform 6.4.0,
  • jboss enterprise application platform 7.1.0,
  • openshift container platform 3.11,
  • openshift container platform 4.1,
  • openstack 13,
  • retail integration bus 15.0,
  • retail integration bus 16.0,
  • retail xstore point of service 15.0,
  • retail xstore point of service 16.0,
  • retail xstore point of service 17.0,
  • retail xstore point of service 7.1,
  • satellite 6.4,
  • satellite capsule 6.4,
  • virtualization 4.0,
  • virtualization 4.2,
  • virtualization host 4.0,
  • weblogic server 12.2.1.3.0

References

Advisory

Additional Info

Technical Analysis