vulnerability

SUSE: CVE-2018-1656: SUSE Linux Security Advisory

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Aug 20, 2018
Added
Sep 1, 2018
Modified
Feb 8, 2021

Description

The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files. IBM X-Force ID: 144882.

Solutions

suse-upgrade-java-1_7_0-ibmsuse-upgrade-java-1_7_0-ibm-alsasuse-upgrade-java-1_7_0-ibm-develsuse-upgrade-java-1_7_0-ibm-jdbcsuse-upgrade-java-1_7_0-ibm-pluginsuse-upgrade-java-1_7_1-ibmsuse-upgrade-java-1_7_1-ibm-alsasuse-upgrade-java-1_7_1-ibm-develsuse-upgrade-java-1_7_1-ibm-jdbcsuse-upgrade-java-1_7_1-ibm-pluginsuse-upgrade-java-1_8_0-ibmsuse-upgrade-java-1_8_0-ibm-alsasuse-upgrade-java-1_8_0-ibm-develsuse-upgrade-java-1_8_0-ibm-plugin
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.