CVE-2018-2627 Details
Description
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Installer). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to the Windows installer only. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| oracle jdk | 1.8.0 update152 9.0.1 |
CPE
Remediation
| |
| oracle jre | 1.8.0 update152 9.0.1 |
CPE
Remediation
| |
| redhat satellite | 5.8 |
CPE
Remediation
| |
| netapp active iq unified manager | >= 7.3 >= 9.5 |
CPE
Remediation
| |
| netapp cloud backup | All versions |
CPE
Remediation
| |
| netapp e-series santricity management plug-ins | All versions |
CPE
Remediation
| |
| netapp e-series santricity os controller | >= 11.0, <= 11.70.1 |
CPE
Remediation
| |
| netapp e-series santricity storage manager | All versions |
CPE
Remediation
| |
| netapp e-series santricity web services | All versions |
CPE
Remediation
| |
| netapp oncommand insight | All versions |
CPE
Remediation
| |
| netapp oncommand shift | All versions |
CPE
Remediation
| |
| netapp oncommand unified manager | All versions |
CPE
Remediation
| |
| netapp oncommand workflow automation | All versions |
CPE
Remediation
| |
| netapp plug-in for symantec netbackup | All versions |
CPE
Remediation
| |
| netapp santricity cloud connector | All versions |
CPE
Remediation
| |
| netapp snapmanager | All versions |
CPE
Remediation
| |
| netapp storage replication adapter for clustered data ontap | >= 7.2 |
CPE
Remediation
| |
| netapp storagegrid | <= 9.0.4 |
CPE
Remediation
| |
| netapp vasa provider for clustered data ontap | >= 7.2 6.0 |
CPE
Remediation
| |
| netapp virtual storage console | >= 7.2 6.0 |
CPE
Remediation
| |
Change History
15 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 6, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 21, 2023 | Reanalysis | [email protected] |
| Aug 12, 2022 | Modified Analysis | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| Sep 8, 2020 | CPE Deprecation Remap | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Nov 30, 2018 | CVE Modified | [email protected] |
| May 17, 2018 | CVE Modified | [email protected] |
| Feb 1, 2018 | Initial Analysis | [email protected] |
| Jan 20, 2018 | CVE Modified | [email protected] |
| Jan 18, 2018 | CVE Modified | [email protected] |