Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-10237


Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.


Published

2018-04-26T21:29:00.230

Last Modified

2024-11-21T03:41:04.663

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-770

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application google guava < 24.1.1 Yes
Application redhat openshift_container_platform 3.11 Yes
Application redhat openstack 13 Yes
Application redhat satellite 6.4 Yes
Application redhat satellite_capsule 6.4 Yes
Application redhat virtualization 4.2 Yes
Application redhat virtualization_host 4.0 Yes
Application redhat jboss_enterprise_application_platform 6.0.0 Yes
Application redhat jboss_enterprise_application_platform 6.4.0 Yes
Application redhat jboss_enterprise_application_platform 7.1.0 Yes
Application redhat openshift_container_platform 4.1 Yes
Application redhat virtualization 4.0 Yes
Application redhat virtualization_host 4.0 Yes
Operating System redhat enterprise_linux 7.0 No
Application redhat jboss_enterprise_application_platform 6.0.0 Yes
Application redhat jboss_enterprise_application_platform 6.4.0 Yes
Operating System redhat enterprise_linux 5.0 No
Application redhat jboss_enterprise_application_platform 6.0.0 Yes
Application redhat jboss_enterprise_application_platform 6.4.0 Yes
Application redhat jboss_enterprise_application_platform 7.1.0 Yes
Operating System redhat enterprise_linux 6.0 No
Application oracle banking_payments ≤ 14.4.0 Yes
Application oracle communications_ip_service_activator 7.3.0 Yes
Application oracle communications_ip_service_activator 7.4.0 Yes
Application oracle customer_management_and_segmentation_foundation 18.0 Yes
Application oracle database_server 12.2.0.1 Yes
Application oracle database_server 18c Yes
Application oracle database_server 19c Yes
Application oracle flexcube_investor_servicing 12.1.0 Yes
Application oracle flexcube_investor_servicing 12.3.0 Yes
Application oracle flexcube_investor_servicing 12.4.0 Yes
Application oracle flexcube_investor_servicing 14.0.0 Yes
Application oracle flexcube_investor_servicing 14.1.0 Yes
Application oracle flexcube_private_banking 12.0.0 Yes
Application oracle flexcube_private_banking 12.1.0 Yes
Application oracle retail_integration_bus 15.0 Yes
Application oracle retail_integration_bus 16.0 Yes
Application oracle retail_xstore_point_of_service 7.1 Yes
Application oracle retail_xstore_point_of_service 15.0 Yes
Application oracle retail_xstore_point_of_service 16.0 Yes
Application oracle retail_xstore_point_of_service 17.0 Yes
Application oracle weblogic_server 12.2.1.3.0 Yes

References