CVE-2017-10388
Summary
| CVE | CVE-2017-10388 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-19 17:29:00 UTC |
| Updated | 2022-10-06 18:57:00 UTC |
| Description | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: Applies to the Java SE Kerberos client. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Netapp | Active Iq Unified Manager | All | All | All | All |
| Application | Netapp | Active Iq Unified Manager | All | All | All | All |
| Application | Netapp | Cloud Backup | - | All | All | All |
| Application | Netapp | E-series Santricity Management Plug-ins | - | All | All | All |
| Application | Netapp | E-series Santricity Os Controller | All | All | All | All |
| Application | Netapp | E-series Santricity Storage Manager | - | All | All | All |
| Application | Netapp | E-series Santricity Web Services | - | All | All | All |
| Application | Netapp | Element Software | - | All | All | All |
| Application | Netapp | Oncommand Balance | - | All | All | All |
| Application | Netapp | Oncommand Insight | - | All | All | All |
| Application | Netapp | Oncommand Performance Manager | - | All | All | All |
| Application | Netapp | Oncommand Shift | - | All | All | All |
| Application | Netapp | Oncommand Unified Manager | - | All | All | All |
| Application | Netapp | Oncommand Unified Manager | All | All | All | All |
| Application | Netapp | Oncommand Unified Manager | All | All | All | All |
| Application | Netapp | Oncommand Workflow Automation | - | All | All | All |
| Application | Netapp | Plug-in For Symantec Netbackup | - | All | All | All |
| Application | Netapp | Snapmanager | - | All | All | All |
| Application | Netapp | Snapmanager | - | All | All | All |
| Application | Netapp | Steelstore Cloud Integrated Storage | - | All | All | All |
| Application | Netapp | Storage Replication Adapter For Clustered Data Ontap | All | All | All | All |
| Application | Netapp | Storage Replication Adapter For Clustered Data Ontap | All | All | All | All |
| Application | Netapp | Vasa Provider For Clustered Data Ontap | All | All | All | All |
| Application | Netapp | Vasa Provider For Clustered Data Ontap | 6.0 | All | All | All |
| Application | Netapp | Virtual Storage Console | All | All | All | All |
| Application | Netapp | Virtual Storage Console | 6.0 | All | All | All |
| Application | Oracle | Jdk | 1.6.0 | update161 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update_161 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update151 | All | All |
| Application | Oracle | Jdk | 1.8.0 | update144 | All | All |
| Application | Oracle | Jdk | 1.9.0 | All | All | All |
| Application | Oracle | Jdk | 1.6.0 | update_161 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update151 | All | All |
| Application | Oracle | Jdk | 1.8.0 | update144 | All | All |
| Application | Oracle | Jdk | 1.9.0 | All | All | All |
| Application | Oracle | Jre | 1.6.0 | update161 | All | All |
| Application | Oracle | Jre | 1.6.0 | update_161 | All | All |
| Application | Oracle | Jre | 1.7.0 | update151 | All | All |
| Application | Oracle | Jre | 1.7.0 | update_151 | All | All |
| Application | Oracle | Jre | 1.8.0 | update144 | All | All |
| Application | Oracle | Jre | 1.8.0 | update_144 | All | All |
| Application | Oracle | Jre | 1.9.0 | All | All | All |
| Application | Oracle | Jre | 1.6.0 | update_161 | All | All |
| Application | Oracle | Jre | 1.7.0 | update_151 | All | All |
| Application | Oracle | Jre | 1.8.0 | update_144 | All | All |
| Application | Oracle | Jre | 1.9.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Desktop | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Desktop | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Eus | 7.4 | All | All | All |
| Operating System | Redhat | Enterprise Linux Eus | 7.5 | All | All | All |
| Operating System | Redhat | Enterprise Linux Eus | 7.6 | All | All | All |
| Operating System | Redhat | Enterprise Linux Eus | 7.7 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Aus | 7.4 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Aus | 7.6 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Aus | 7.7 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Tus | 7.4 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Tus | 7.6 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Tus | 7.7 | All | All | All |
| Operating System | Redhat | Enterprise Linux Workstation | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Workstation | 7.0 | All | All | All |
| Application | Redhat | Satellite | 5.8 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Oracle Java SE Multiple Flaws Let Remote Users Access and Modify Data, Deny Service, and Gain Elevated Privileges - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Oracle Java SE CVE-2017-10388 Remote Security Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Oracle JDK/JRE: Multiple vulnerabilities (GLSA 201710-31) — Gentoo security | GENTOO | security.gentoo.org | |
| Synology Inc. | CONFIRM | www.synology.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| IcedTea: Multiple vulnerabilities (GLSA 201711-14) — Gentoo security | GENTOO | security.gentoo.org | |
| [SECURITY] [DLA 1187-1] openjdk-7 security update | MLIST | lists.debian.org | |
| Debian -- Security Information -- DSA-4015-1 openjdk-8 | DEBIAN | www.debian.org | |
| October 2017 Java Platform Standard Edition Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Debian -- Security Information -- DSA-4048-1 openjdk-7 | DEBIAN | www.debian.org | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Oracle Critical Patch Update - October 2017 | CONFIRM | www.oracle.com | Patch |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378276 Virtuozzo Linux Security Update for java-1.8.0-openjdk-devel-debug (VZLSA-2017:2998)
- 378308 Virtuozzo Linux Security Update for java-1.7.0-openjdk-accessibility (VZLSA-2017:3392)
- 710463 Gentoo Linux Oracle Java Development Toolkit/Java Runtime Error Multiple Vulnerabilities (GLSA 201710-31)
- 710564 Gentoo Linux IcedTea Multiple Vulnerabilities (GLSA 201711-14)