← Back to CVE List
Vulnerability Intelligence Report

CVE-2018-10237

Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.

No Active Exploit Signals
CVSS Base Score
5.9
MEDIUM
EPSS Probability:5.12%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
google guava all
redhat openshift_container_platform 3.11, 4.1
redhat openstack 13
redhat satellite 6.4
redhat satellite_capsule 6.4
redhat virtualization 4.2, 4.0
redhat virtualization_host 4.0
redhat jboss_enterprise_application_platform 6.0.0, 6.4.0, 7.1.0
redhat enterprise_linux 7.0, 5.0, 6.0
oracle banking_payments all
oracle communications_ip_service_activator 7.3.0, 7.4.0
oracle customer_management_and_segmentation_foundation 18.0
oracle database_server 12.2.0.1, 18c, 19c
oracle flexcube_investor_servicing 12.1.0, 12.3.0, 12.4.0, 14.0.0, 14.1.0
oracle flexcube_private_banking 12.0.0, 12.1.0
oracle retail_integration_bus 15.0, 16.0
oracle retail_xstore_point_of_service 7.1, 15.0, 16.0, 17.0
oracle weblogic_server 12.2.1.3.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
5.119%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2018-04-20T00:00:00
Published2018-04-26T21:00:00
Patch Date2018-04-26
Last Updated2024-08-05T07:32:01

LINK COPIED TO CLIPBOARD