CVE-2018-1656: IBM SDK

Medium severity, CVSS 6.5. EPSS: 4.5% chance of exploitation in the next 30 days.

The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files. IBM X-Force ID: 144882.

Affected products

  • IBM SDK: version 6.0 only; version 7.0 only; version 8.0 only
  • Oracle Enterprise Manager Base Platform: version 13.2.0.0.0 only; version 13.3.0.0.0 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
  • Red Hat Satellite: version 5.6 only; version 5.7 only; version 5.8 only

Published 2018-08-20. Last modified 2026-06-17.