Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-10388

Опубликовано: 17 окт. 2017
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: Applies to the Java SE Kerberos client. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).

It was discovered that the Kerberos client implementation in the Libraries component of OpenJDK used the sname field from the plain text part rather than encrypted part of the KDC reply message. A man-in-the-middle attacker could possibly use this flaw to impersonate Kerberos services to Java applications acting as Kerberos clients.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6java-1.6.0-ibmWill not fix
Oracle Java for Red Hat Enterprise Linux 6java-1.8.0-oracleFixedRHSA-2017:299923.10.2017
Oracle Java for Red Hat Enterprise Linux 6java-1.7.0-oracleFixedRHSA-2017:304624.10.2017
Oracle Java for Red Hat Enterprise Linux 6java-1.6.0-sunFixedRHSA-2017:304724.10.2017
Oracle Java for Red Hat Enterprise Linux 7java-1.8.0-oracleFixedRHSA-2017:299923.10.2017
Oracle Java for Red Hat Enterprise Linux 7java-1.7.0-oracleFixedRHSA-2017:304624.10.2017
Oracle Java for Red Hat Enterprise Linux 7java-1.6.0-sunFixedRHSA-2017:304724.10.2017
Red Hat Enterprise Linux 6java-1.8.0-openjdkFixedRHSA-2017:299820.10.2017
Red Hat Enterprise Linux 6java-1.7.0-openjdkFixedRHSA-2017:339206.12.2017
Red Hat Enterprise Linux 6 Supplementaryjava-1.8.0-ibmFixedRHSA-2017:326728.11.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-345
https://bugzilla.redhat.com/show_bug.cgi?id=1502038OpenJDK: use of unprotected sname in Kerberos client (Libraries, 8178794)

EPSS

Процентиль: 66%
0.00532
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: Applies to the Java SE Kerberos client. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).

CVSS3: 7.5
nvd
больше 7 лет назад

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: Applies to the Java SE Kerberos client. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).

CVSS3: 7.5
debian
больше 7 лет назад

Vulnerability in the Java SE, Java SE Embedded component of Oracle Jav ...

CVSS3: 7.5
github
около 3 лет назад

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: Applies to the Java SE Kerberos client. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).

oracle-oval
больше 7 лет назад

ELSA-2017-2998: java-1.8.0-openjdk security update (CRITICAL)

EPSS

Процентиль: 66%
0.00532
Низкий

6.8 Medium

CVSS3