MEDIUM · 5.9

CVE-2018-10237

Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize att...

Vulnerability Description

Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
GoogleGuava>= 11.0, < 24.1.1
RedhatOpenshift Container Platform3.11
RedhatOpenstack13
RedhatSatellite6.4
RedhatSatellite Capsule6.4
RedhatVirtualization4.2
RedhatVirtualization Host4.0
RedhatJboss Enterprise Application Platform6.0.0
RedhatEnterprise Linux7.0
OracleBanking Payments>= 14.1.0, <= 14.4.0
OracleCommunications Ip Service Activator7.3.0
OracleCustomer Management And Segmentation Foundation18.0
OracleDatabase Server12.2.0.1
OracleFlexcube Investor Servicing12.1.0
OracleFlexcube Private Banking12.0.0
OracleRetail Integration Bus15.0
OracleRetail Xstore Point Of Service7.1
OracleWeblogic Server12.2.1.3.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-10237?

CVE-2018-10237 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize att...

How severe is CVE-2018-10237?

CVE-2018-10237 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-10237?

Check the references section above for vendor advisories and patch information. Affected products include: Google Guava, Redhat Openshift Container Platform, Redhat Openstack, Redhat Satellite, Redhat Satellite Capsule.