CVE-2018-10237
Last modified
CVE-2018-10237 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.. EPSS estimates a 5.12% chance of exploitation in the next 30 days.
Description
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Guava | >= 11.0, < 24.1.1 | |
| Redhat | Openshift Container Platform | 3.11 |
| Redhat | Openstack | 13 |
| Redhat | Satellite | 6.4 |
| Redhat | Satellite Capsule | 6.4 |
| Redhat | Virtualization | 4.2 |
| Redhat | Virtualization Host | 4.0 |
| Redhat | Jboss Enterprise Application Platform | 6.0.0 |
| Redhat | Jboss Enterprise Application Platform | 6.4.0 |
| Redhat | Jboss Enterprise Application Platform | 7.1.0 |
| Redhat | Openshift Container Platform | 4.1 |
| Redhat | Virtualization | 4.0 |
| Oracle | Banking Payments | >= 14.1.0, <= 14.4.0 |
| Oracle | Communications Ip Service Activator | 7.3.0 |
| Oracle | Communications Ip Service Activator | 7.4.0 |
| Oracle | Customer Management And Segmentation Foundation | 18.0 |
| Oracle | Database Server | 12.2.0.1 |
| Oracle | Database Server | 18c |
| Oracle | Database Server | 19c |
| Oracle | Flexcube Investor Servicing | 12.1.0 |
| Oracle | Flexcube Investor Servicing | 12.3.0 |
| Oracle | Flexcube Investor Servicing | 12.4.0 |
| Oracle | Flexcube Investor Servicing | 14.0.0 |
| Oracle | Flexcube Investor Servicing | 14.1.0 |
| Oracle | Flexcube Private Banking | 12.0.0 |
| Oracle | Flexcube Private Banking | 12.1.0 |
| Oracle | Retail Integration Bus | 15.0 |
| Oracle | Retail Integration Bus | 16.0 |
| Oracle | Retail Xstore Point Of Service | 7.1 |
| Oracle | Retail Xstore Point Of Service | 15.0 |
| Oracle | Retail Xstore Point Of Service | 16.0 |
| Oracle | Retail Xstore Point Of Service | 17.0 |
| Oracle | Weblogic Server | 12.2.1.3.0 |
References
- http://www.securitytracker.com/id/1041707Broken Link
- https://access.redhat.com/errata/RHSA-2018:2423Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2424Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2425Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2428Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2598Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2643Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2740Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2741Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2742Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2743Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2927Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2858Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3149Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- http://www.securitytracker.com/id/1041707Broken Link
- https://access.redhat.com/errata/RHSA-2018:2423Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2424Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2425Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2428Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2598Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2643Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2740Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2741Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2742Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2743Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2927Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2858Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3149Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10237?
How severe is CVE-2018-10237?
How do I fix CVE-2018-10237?
Are you affected by CVE-2018-10237?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
