CVE-2018-1313
Description
A specially-crafted network packet can boot a user-controlled database on Apache Derby Network Server without a restrictive Java Security Manager.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A specially-crafted network packet can boot a user-controlled database on Apache Derby Network Server without a restrictive Java Security Manager.
Vulnerability
Apache Derby versions 10.3.1.4 to 10.14.1.0 (inclusive) contain a vulnerability in the Network Server component. A specially-crafted network packet can be sent to request the server to boot a database whose location and contents are under the attacker's control. The attack succeeds if the server is not running with a Java Security Manager policy file; if a policy file is used, it must permit reading the database location for the attack to work. The default Derby Network Server policy file distributed with affected releases is permissive, allowing the attack by default [1].
Exploitation
The attacker requires network access to the Derby Network Server. No authentication is needed. The attacker sends a crafted network packet to the server, instructing it to boot a database location chosen by the attacker. If the server is not protected by a Java Security Manager policy, the attack succeeds immediately. Even with a policy file, the default policy included in the distribution is permissive enough to allow the attack [1].
Impact
Successful exploitation allows the attacker to boot a database under their control on the server. This can lead to unauthorized data access or arbitrary code execution within the context of the Derby process, depending on the contents of the attacker-supplied database [1].
Mitigation
Apache Derby recommends upgrading to version 10.14.2.1 or later, which addresses this issue. As a workaround, users of affected versions should deploy a restrictive Java Security Manager policy file that limits database boot locations. The default permissive policy should not be used in production environments. No KEV listing is available for this CVE [1].
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.derby:derbyMaven | >= 10.3.1.4, < 10.14.2.0 | 10.14.2.0 |
Affected products
2- Apache Software Foundation/Apache Derbyv5Range: 10.3.1.4 to 10.14.1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
17- github.com/advisories/GHSA-42xw-p62x-hwcfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-1313ghsaADVISORY
- www.securityfocus.com/bid/104140ghsavdb-entryx_refsource_BIDWEB
- lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3EghsaWEB
- lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3EghsaWEB
- lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r437d94437e6aef31af689b1e7025d024d676fd1ea9901d74e3e9ae48%40%3Cissues.hive.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/r437d94437e6aef31af689b1e7025d024d676fd1ea9901d74e3e9ae48@%3Cissues.hive.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r6755f48d4f5e44e39bba7dbf8d746678239d7f1f2cc108125519ce53%40%3Cissues.hive.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/r6755f48d4f5e44e39bba7dbf8d746678239d7f1f2cc108125519ce53@%3Cissues.hive.apache.org%3EghsaWEB
- lists.apache.org/thread.html/re29ab90978e6c997377fb975f674f7514f6beb642bbf79deb45477e5%40%3Cdev.hive.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/re29ab90978e6c997377fb975f674f7514f6beb642bbf79deb45477e5@%3Cdev.hive.apache.org%3EghsaWEB
- markmail.org/message/akkappppxcdqrgxkghsamailing-listx_refsource_MLISTWEB
- www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.