CVE-2017-10356
published 2017-10-19CVE-2017-10356: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE…
PriorityP426medium6.2CVSS 3.1
AVLACLPRNUINSUCHINAN
EPSS
0.75%
51.0th percentile
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, Java SE Embedded, JRockit executes to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 6.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjdk-8 | < openjdk-8 8u151-b12-1 (sid) | openjdk-8 8u151-b12-1 (sid) |
| netapp | active_iq_unified_manager | >= 7.3 | — |
| netapp | active_iq_unified_manager | >= 9.5 | — |
| netapp | e-series_santricity_os_controller | 11.0 – 11.70.1 | — |
| netapp | oncommand_unified_manager | <= 7.1 | — |
| netapp | storage_replication_adapter_for_clustered_data_ontap | >= 7.2 | — |
| netapp | vasa_provider_for_clustered_data_ontap | — | — |
| netapp | vasa_provider_for_clustered_data_ontap | >= 7.2 | — |
| netapp | virtual_storage_console | — | — |
| netapp | virtual_storage_console | >= 7.2 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
CVSS provenance
nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv6.8MEDIUM
vendor_ubuntu6.8MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-48hc-p2wv-prx2: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security)
ghsa_unreviewed·2022-05-13
CVE-2017-10356 [MEDIUM] CWE-200 GHSA-48hc-p2wv-prx2: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security)
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, Java SE Embedded, JRockit executes to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without
OSV
openjdk-7 vulnerabilities
osv·2017-11-29·CVSS 6.8
CVE-2017-10274 [MEDIUM] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
It was discovered that the Smart Card IO subsystem in OpenJDK did not
properly maintain state. An attacker could use this to specially construct
an untrusted Java application or applet to gain access to a smart card,
bypassing sandbox restrictions. (CVE-2017-10274)
Gaston Traberg discovered that the Serialization component of OpenJDK did
not properly limit the amount of memory allocated when performing
deserializations. An attacker could use this to cause a denial of service
(memory exhaustion). (CVE-2017-10281)
It was discovered that the Remote Method Invocation (RMI) component in
OpenJDK did not properly handle unreferenced objects. An attacker could use
this to specially construct an untrusted Java application or applet that
could escape sandbox restrictions
OSV
openjdk-8 vulnerabilities
osv·2017-11-08·CVSS 6.8
CVE-2017-10274 [MEDIUM] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
It was discovered that the Smart Card IO subsystem in OpenJDK did not
properly maintain state. An attacker could use this to specially construct
an untrusted Java application or applet to gain access to a smart card,
bypassing sandbox restrictions. (CVE-2017-10274)
Gaston Traberg discovered that the Serialization component of OpenJDK did
not properly limit the amount of memory allocated when performing
deserializations. An attacker could use this to cause a denial of service
(memory exhaustion). (CVE-2017-10281)
It was discovered that the Remote Method Invocation (RMI) component in
OpenJDK did not properly handle unreferenced objects. An attacker could use
this to specially construct an untrusted Java application or applet that
could escape sandbox restrictions
OSV
CVE-2017-10356: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security)
osv·2017-10-19·CVSS 6.2
CVE-2017-10356 [MEDIUM] CVE-2017-10356: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security)
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, Java SE Embedded, JRockit executes to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2017-11-29·CVSS 6.8
CVE-2017-10274 [MEDIUM] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
It was discovered that the Smart Card IO subsystem in OpenJDK did not
properly maintain state. An attacker could use this to specially construct
an untrusted Java application or applet to gain access to a smart card,
bypassing sandbox restrictions. (CVE-2017-10274)
Gaston Traberg discovered that the Serialization component of OpenJDK did
not properly limit the amount of memory allocated when performing
deserializations. An attacker could use this to cause a denial of service
(memory exhaustion). (CVE-2017-10281)
It was discovered that the Remote Method Invocation (RMI) component in
OpenJDK did not properly handle unreferenced objects. An attacker could use
this to specially construct an untrusted
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2017-11-08·CVSS 6.8
CVE-2017-10274 [MEDIUM] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
It was discovered that the Smart Card IO subsystem in OpenJDK did not
properly maintain state. An attacker could use this to specially construct
an untrusted Java application or applet to gain access to a smart card,
bypassing sandbox restrictions. (CVE-2017-10274)
Gaston Traberg discovered that the Serialization component of OpenJDK did
not properly limit the amount of memory allocated when performing
deserializations. An attacker could use this to cause a denial of service
(memory exhaustion). (CVE-2017-10281)
It was discovered that the Remote Method Invocation (RMI) component in
OpenJDK did not properly handle unreferenced objects. An attacker could use
this to specially construct an untrusted
Red Hat
OpenJDK: weak protection of key stores against brute forcing (Security, 8181692)
vendor_redhat·2017-10-17·CVSS 6.2
CVE-2017-10356 [MEDIUM] CWE-327 OpenJDK: weak protection of key stores against brute forcing (Security, 8181692)
OpenJDK: weak protection of key stores against brute forcing (Security, 8181692)
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, Java SE Embedded, JRockit executes to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It
Debian
CVE-2017-10356: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java...
vendor_debian·2017·CVSS 6.2
CVE-2017-10356 [MEDIUM] CVE-2017-10356: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java...
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, Java SE Embedded, JRockit executes to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without
No detection rules found.
No public exploits indexed.
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/101413http://www.securitytracker.com/id/1039596https://access.redhat.com/errata/RHSA-2017:2998https://access.redhat.com/errata/RHSA-2017:2999https://access.redhat.com/errata/RHSA-2017:3046https://access.redhat.com/errata/RHSA-2017:3047https://access.redhat.com/errata/RHSA-2017:3264https://access.redhat.com/errata/RHSA-2017:3267https://access.redhat.com/errata/RHSA-2017:3268https://access.redhat.com/errata/RHSA-2017:3392https://access.redhat.com/errata/RHSA-2017:3453https://lists.debian.org/debian-lts-announce/2017/11/msg00033.htmlhttps://security.gentoo.org/glsa/201710-31https://security.gentoo.org/glsa/201711-14https://security.netapp.com/advisory/ntap-20171019-0001/https://www.debian.org/security/2017/dsa-4015https://www.debian.org/security/2017/dsa-4048http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/101413http://www.securitytracker.com/id/1039596https://access.redhat.com/errata/RHSA-2017:2998https://access.redhat.com/errata/RHSA-2017:2999https://access.redhat.com/errata/RHSA-2017:3046https://access.redhat.com/errata/RHSA-2017:3047https://access.redhat.com/errata/RHSA-2017:3264https://access.redhat.com/errata/RHSA-2017:3267https://access.redhat.com/errata/RHSA-2017:3268https://access.redhat.com/errata/RHSA-2017:3392https://access.redhat.com/errata/RHSA-2017:3453https://lists.debian.org/debian-lts-announce/2017/11/msg00033.htmlhttps://security.gentoo.org/glsa/201710-31https://security.gentoo.org/glsa/201711-14https://security.netapp.com/advisory/ntap-20171019-0001/https://www.debian.org/security/2017/dsa-4015https://www.debian.org/security/2017/dsa-4048
2017-10-19
Published