CVE-2018-5407
MEDIUM
4,7
Source: [email protected]
Attack Vector: local
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none
LOW
1,9
Source: [email protected]
Access Vector: local
Access Complexity: medium
Authentication: none
Confidentiality: partial
Integrity: none
Availability: none
Description
AI Translation Available
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0064
Percentile
0,7th
Updated
EPSS Score Trend (Last 90 Days)
200
Exposure of Sensitive Information to an Unauthorized Actor
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
Technologies:
Mobile, Not Technology-Specific, Web Based
203
Observable Discrepancy
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Access Control
Potential Impacts:
Read Application Data
Bypass Protection Mechanism
Applicable Platforms
All platforms may be affected
Exploit
Intel (Skylake / Kaby Lake) - 'PortSmash' CPU …
Intel (Skylake / Kaby Lake) - 'PortSmash' CPU SMT Side-Channel
View Exploit Code →
Application
Primavera P6 Enterprise Project Portfolio Management by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:18.8:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Ubuntu Linux by Canonical
CPE Identifier
View Detailed Analysis
cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Nessus by Tenable
Version Range Affected
To
8.1.1
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Openssl by Openssl
Version Range Affected
From
1.0.2
(inclusive)
To
1.0.2q
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Application Server by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:application_server:1.0.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Ubuntu Linux by Canonical
CPE Identifier
View Detailed Analysis
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Primavera P6 Enterprise Project Portfolio Management by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:16.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Enterprise Linux Desktop by Redhat
CPE Identifier
View Detailed Analysis
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Primavera P6 Enterprise Project Portfolio Management by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:15.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Enterprise Manager Base Platform by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:enterprise_manager_base_platform:13.2.0.0.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Peoplesoft Enterprise Peopletools by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Node.Js by Nodejs
Version Range Affected
From
8.0.0
(inclusive)
To
8.11.4
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Node.Js by Nodejs
Version Range Affected
From
10.0.0
(inclusive)
To
10.9.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Node.Js by Nodejs
Version Range Affected
To
6.14.4
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Enterprise Linux Server by Redhat
CPE Identifier
View Detailed Analysis
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Enterprise Linux Server by Redhat
CPE Identifier
View Detailed Analysis
cpe:2.3:o:redhat:enterprise_linux_server:7.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Primavera P6 Enterprise Project Portfolio Management by Oracle
Version Range Affected
From
17.7
(inclusive)
To
17.12
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Peoplesoft Enterprise Peopletools by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Mysql Enterprise Backup by Oracle
Version Range Affected
From
3.12.4
(inclusive)
To
4.1.2
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:mysql_enterprise_backup:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Enterprise Linux Workstation by Redhat
CPE Identifier
View Detailed Analysis
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Primavera P6 Enterprise Project Portfolio Management by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:8.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Tuxedo by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:tuxedo:12.1.1.0.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Primavera P6 Enterprise Project Portfolio Management by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:15.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Enterprise Manager Base Platform by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:enterprise_manager_base_platform:12.1.0.5.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Primavera P6 Enterprise Project Portfolio Management by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:16.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Api Gateway by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:api_gateway:11.1.2.4.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Enterprise Manager Ops Center by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Enterprise Linux Server Aus by Redhat
CPE Identifier
View Detailed Analysis
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vm Virtualbox by Oracle
Version Range Affected
To
6.0.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Ubuntu Linux by Canonical
CPE Identifier
View Detailed Analysis
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Openssl by Openssl
Version Range Affected
From
1.1.0
(inclusive)
To
1.1.0i
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Enterprise Linux Server Tus by Redhat
CPE Identifier
View Detailed Analysis
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Application Server by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:application_server:0.9.8:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Enterprise Linux Server Eus by Redhat
CPE Identifier
View Detailed Analysis
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Debian Linux by Debian
CPE Identifier
View Detailed Analysis
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Enterprise Manager Base Platform by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:enterprise_manager_base_platform:13.3.0.0.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Peoplesoft Enterprise Peopletools by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Mysql Enterprise Backup by Oracle
Version Range Affected
To
3.12.3
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:mysql_enterprise_backup:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Debian Linux by Debian
CPE Identifier
View Detailed Analysis
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Application Server by Oracle
CPE Identifier
View Detailed Analysis
cpe:2.3:a:oracle:application_server:1.0.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Ubuntu Linux by Canonical
CPE Identifier
View Detailed Analysis
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://access.redhat.com/errata/RHSA-2019:0483
https://access.redhat.com/errata/RHSA-2019:0651
https://access.redhat.com/errata/RHSA-2019:0652
https://access.redhat.com/errata/RHSA-2019:2125
https://access.redhat.com/errata/RHSA-2019:3929
https://access.redhat.com/errata/RHSA-2019:3931
https://access.redhat.com/errata/RHSA-2019:3932
https://access.redhat.com/errata/RHSA-2019:3933
https://access.redhat.com/errata/RHSA-2019:3935
https://eprint.iacr.org/2018/1060.pdf
https://github.com/bbbrumley/portsmash
https://lists.debian.org/debian-lts-announce/2018/11/msg00024.html
https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/
https://security.gentoo.org/glsa/201903-10
https://security.netapp.com/advisory/ntap-20181126-0001/
https://support.f5.com/csp/article/K49711130?utm_source=f5support&%3Butm_med…
https://usn.ubuntu.com/3840-1/
https://www.debian.org/security/2018/dsa-4348
https://www.debian.org/security/2018/dsa-4355
https://www.exploit-db.com/exploits/45785/
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://www.tenable.com/security/tns-2018-16
https://www.tenable.com/security/tns-2018-17
http://www.securityfocus.com/bid/105897
https://access.redhat.com/errata/RHSA-2019:0483
https://access.redhat.com/errata/RHSA-2019:0651
https://access.redhat.com/errata/RHSA-2019:0652
https://access.redhat.com/errata/RHSA-2019:2125
https://access.redhat.com/errata/RHSA-2019:3929
https://access.redhat.com/errata/RHSA-2019:3931
https://access.redhat.com/errata/RHSA-2019:3932
https://access.redhat.com/errata/RHSA-2019:3933
https://access.redhat.com/errata/RHSA-2019:3935
https://eprint.iacr.org/2018/1060.pdf
https://github.com/bbbrumley/portsmash
https://lists.debian.org/debian-lts-announce/2018/11/msg00024.html
https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/
https://security.gentoo.org/glsa/201903-10
https://security.netapp.com/advisory/ntap-20181126-0001/
https://support.f5.com/csp/article/K49711130?utm_source=f5support&%3Butm_med…
https://usn.ubuntu.com/3840-1/
https://www.debian.org/security/2018/dsa-4348
https://www.debian.org/security/2018/dsa-4355
https://www.exploit-db.com/exploits/45785/
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://www.tenable.com/security/tns-2018-16
https://www.tenable.com/security/tns-2018-17
http://www.securityfocus.com/bid/105897