CVE-2017-3533
published 2017-04-24CVE-2017-3533: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java…
PriorityP416low3.7CVSS 3.0
AVNACHPRNUINSUCNILAN
EPSS
2.58%
83.5th percentile
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via FTP to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | openjdk-8 | < openjdk-8 8u131-b11-1 (sid) | openjdk-8 8u131-b11-1 (sid) |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jrockit | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.2MEDIUM
vendor_ubuntu4.2MEDIUM
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h4pv-vpf9-9gwp: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking)
ghsa_unreviewed·2022-05-13
CVE-2017-3533 [MEDIUM] GHSA-h4pv-vpf9-9gwp: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking)
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via FTP to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandb
OSV
openjdk-7 regression
osv·2017-05-18·CVSS 4.2
CVE-2017-3509 [MEDIUM] openjdk-7 regression
openjdk-7 regression
USN-3275-2 fixed vulnerabilities in OpenJDK 7. Unfortunately, the
update introduced a regression when handling TLS handshakes. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that OpenJDK improperly re-used cached NTLM
connections in some situations. A remote attacker could possibly
use this to cause a Java application to perform actions with the
credentials of a different user. (CVE-2017-3509)
It was discovered that an untrusted library search path flaw existed
in the Java Cryptography Extension (JCE) component of OpenJDK. A
local attacker could possibly use this to gain the privileges of a
Java application. (CVE-2017-3511)
It was discovered that the Java API for XML Processing (JAXP) component
in O
OSV
openjdk-7 vulnerabilities
osv·2017-05-15·CVSS 4.2
CVE-2017-3509 [MEDIUM] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
USN-3275-1 fixed vulnerabilities in OpenJDK 8. This update provides
the corresponding updates for OpenJDK 7.
Original advisory details:
It was discovered that OpenJDK improperly re-used cached NTLM
connections in some situations. A remote attacker could possibly
use this to cause a Java application to perform actions with the
credentials of a different user. (CVE-2017-3509)
It was discovered that an untrusted library search path flaw existed
in the Java Cryptography Extension (JCE) component of OpenJDK. A
local attacker could possibly use this to gain the privileges of a
Java application. (CVE-2017-3511)
It was discovered that the Java API for XML Processing (JAXP) component
in OpenJDK did not properly enforce size limits when parsing XML
documents. An attack
OSV
openjdk-8 vulnerabilities
osv·2017-05-11·CVSS 4.2
CVE-2017-3509 [MEDIUM] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
It was discovered that OpenJDK improperly re-used cached NTLM
connections in some situations. A remote attacker could possibly
use this to cause a Java application to perform actions with the
credentials of a different user. (CVE-2017-3509)
It was discovered that an untrusted library search path flaw existed
in the Java Cryptography Extension (JCE) component of OpenJDK. A
local attacker could possibly use this to gain the privileges of a
Java application. (CVE-2017-3511)
It was discovered that the Java API for XML Processing (JAXP) component
in OpenJDK did not properly enforce size limits when parsing XML
documents. An attacker could use this to cause a denial of service
(processor and memory consumption). (CVE-2017-3526)
It was discovered that the FTP client
OSV
CVE-2017-3533: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking)
osv·2017-04-24·CVSS 3.7
CVE-2017-3533 [LOW] CVE-2017-3533: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking)
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via FTP to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandb
Ubuntu
OpenJDK 7 regression
vendor_ubuntu·2017-05-18·CVSS 4.2
[MEDIUM] OpenJDK 7 regression
Title: OpenJDK 7 regression
Summary: USN-3275-2 introduced a regression in OpenJDK 7.
USN-3275-2 fixed vulnerabilities in OpenJDK 7. Unfortunately, the
update introduced a regression when handling TLS handshakes. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that OpenJDK improperly re-used cached NTLM
connections in some situations. A remote attacker could possibly
use this to cause a Java application to perform actions with the
credentials of a different user. (CVE-2017-3509)
It was discovered that an untrusted library search path flaw existed
in the Java Cryptography Extension (JCE) component of OpenJDK. A
local attacker could possibly use this to gain the privileges of a
Java application. (CVE-2017-3511)
It was dis
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2017-05-15·CVSS 4.2
CVE-2017-3509 [MEDIUM] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
USN-3275-1 fixed vulnerabilities in OpenJDK 8. This update provides
the corresponding updates for OpenJDK 7.
Original advisory details:
It was discovered that OpenJDK improperly re-used cached NTLM
connections in some situations. A remote attacker could possibly
use this to cause a Java application to perform actions with the
credentials of a different user. (CVE-2017-3509)
It was discovered that an untrusted library search path flaw existed
in the Java Cryptography Extension (JCE) component of OpenJDK. A
local attacker could possibly use this to gain the privileges of a
Java application. (CVE-2017-3511)
It was discovered that the Java API for XML Processing (JAXP) component
in OpenJDK did not
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2017-05-11·CVSS 4.2
CVE-2017-3509 [MEDIUM] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
It was discovered that OpenJDK improperly re-used cached NTLM
connections in some situations. A remote attacker could possibly
use this to cause a Java application to perform actions with the
credentials of a different user. (CVE-2017-3509)
It was discovered that an untrusted library search path flaw existed
in the Java Cryptography Extension (JCE) component of OpenJDK. A
local attacker could possibly use this to gain the privileges of a
Java application. (CVE-2017-3511)
It was discovered that the Java API for XML Processing (JAXP) component
in OpenJDK did not properly enforce size limits when parsing XML
documents. An attacker could use this to cause a denial of service
(processor and memory con
Red Hat
OpenJDK: newline injection in the FTP client (Networking, 8170222)
vendor_redhat·2017-02-18·CVSS 3.7
CVE-2017-3533 [LOW] CWE-20 OpenJDK: newline injection in the FTP client (Networking, 8170222)
OpenJDK: newline injection in the FTP client (Networking, 8170222)
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via FTP to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by s
Debian
CVE-2017-3533: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java...
vendor_debian·2017·CVSS 3.7
CVE-2017-3533 [LOW] CVE-2017-3533: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java...
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via FTP to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandb
No detection rules found.
No public exploits indexed.
http://www.debian.org/security/2017/dsa-3858http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlhttp://www.securityfocus.com/bid/97740http://www.securitytracker.com/id/1038286https://access.redhat.com/errata/RHSA-2017:1108https://access.redhat.com/errata/RHSA-2017:1109https://access.redhat.com/errata/RHSA-2017:1117https://access.redhat.com/errata/RHSA-2017:1118https://access.redhat.com/errata/RHSA-2017:1119https://access.redhat.com/errata/RHSA-2017:1204https://access.redhat.com/errata/RHSA-2017:1220https://access.redhat.com/errata/RHSA-2017:1221https://access.redhat.com/errata/RHSA-2017:1222https://access.redhat.com/errata/RHSA-2017:3453https://security.gentoo.org/glsa/201705-03https://security.gentoo.org/glsa/201707-01http://www.debian.org/security/2017/dsa-3858http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlhttp://www.securityfocus.com/bid/97740http://www.securitytracker.com/id/1038286https://access.redhat.com/errata/RHSA-2017:1108https://access.redhat.com/errata/RHSA-2017:1109https://access.redhat.com/errata/RHSA-2017:1117https://access.redhat.com/errata/RHSA-2017:1118https://access.redhat.com/errata/RHSA-2017:1119https://access.redhat.com/errata/RHSA-2017:1204https://access.redhat.com/errata/RHSA-2017:1220https://access.redhat.com/errata/RHSA-2017:1221https://access.redhat.com/errata/RHSA-2017:1222https://access.redhat.com/errata/RHSA-2017:3453https://security.gentoo.org/glsa/201705-03https://security.gentoo.org/glsa/201707-01
2017-04-24
Published