---
title: "CVE-2018-3150\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2018-3150?format=md
keywords: index, follow
---

# CVE-2018-3150

Publication date 16 October 2018

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**3.7 · Low**

[Score breakdown](https://ubuntu.com/security/CVE-2018-3150?format=md#impact-score)

Toggle side navigation

## Description

Vulnerability in the Java SE component of Oracle Java SE (subcomponent:
Utility). The supported version that is affected is Java SE: 11. Difficult
to exploit vulnerability allows unauthenticated attacker with network
access via multiple protocols to compromise Java SE. Successful attacks of
this vulnerability can result in unauthorized update, insert or delete
access to some of Java SE accessible data. Note: This vulnerability applies
to Java deployments that load and run untrusted code (e.g., code that comes
from the internet) and rely on the Java sandbox for security. This
vulnerability does not apply to Java deployments, typically in servers,
that load and run only trusted code (e.g., code installed by an
administrator). CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).

### From the Ubuntu Security Team

It was discovered that the Utility component of OpenJDK did not
properly ensure all attributes in a JAR were signed before use.
An attacker could use this to specially construct an untrusted Java
application or applet that could escape sandbox restrictions

[Read the notes from the security team](https://ubuntu.com/security/CVE-2018-3150?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| openjdk-8 | 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |
| openjdk-lts | 18.10 cosmic | Fixed 11.0.1+13-2ubuntu1 |
| 18.04 LTS bionic | Fixed 10.0.2+13-1ubuntu0.18.04.3 |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [sbeattie](https://launchpad.net/~sbeattie)

openjdk 10, 11 only

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

3.7 · Low

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | Low |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 3.7 · Low |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3150)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-3150)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2018-3150)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2018-3150)

### Related Ubuntu Security Notices (USN)

+ [USN-3804-1](https://usn.ubuntu.com/USN-3804-1)
+ OpenJDK vulnerabilities
+ 30 October 2018

### Other references

* <http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html>
* <https://www.cve.org/CVERecord?id=CVE-2018-3150>
