Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
References
Link | Resource |
---|---|
http://www.debian.org/security/2017/dsa-3919 | Third Party Advisory |
http://www.debian.org/security/2017/dsa-3954 | Third Party Advisory |
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html | Patch Vendor Advisory |
http://www.securityfocus.com/bid/99788 | Broken Link |
http://www.securitytracker.com/id/1038931 | Broken Link |
https://access.redhat.com/errata/RHSA-2017:1790 | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2017:1791 | Third Party Advisory |
https://cert.vde.com/en-us/advisories/vde-2017-002 | Third Party Advisory |
https://security.gentoo.org/glsa/201709-22 | Third Party Advisory |
https://security.netapp.com/advisory/ntap-20170720-0001/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
06 Oct 2022, 19:00
Type | Values Removed | Values Added |
---|---|---|
References | (REDHAT) https://access.redhat.com/errata/RHSA-2017:1791 - Third Party Advisory | |
References | (BID) http://www.securityfocus.com/bid/99788 - Broken Link | |
References | (DEBIAN) http://www.debian.org/security/2017/dsa-3919 - Third Party Advisory | |
References | (SECTRACK) http://www.securitytracker.com/id/1038931 - Broken Link | |
References | (CONFIRM) https://security.netapp.com/advisory/ntap-20170720-0001/ - Third Party Advisory | |
References | (CONFIRM) https://cert.vde.com/en-us/advisories/vde-2017-002 - Third Party Advisory | |
References | (REDHAT) https://access.redhat.com/errata/RHSA-2017:1790 - Third Party Advisory | |
References | (GENTOO) https://security.gentoo.org/glsa/201709-22 - Third Party Advisory | |
References | (DEBIAN) http://www.debian.org/security/2017/dsa-3954 - Third Party Advisory | |
First Time |
Netapp oncommand Balance
Phoenixcontact fl Mguard Dm Netapp oncommand Unified Manager Netapp steelstore Cloud Integrated Storage Netapp vasa Provider For Clustered Data Ontap Netapp plug-in For Symantec Netbackup Netapp oncommand Shift Debian Phoenixcontact Netapp snapmanager Netapp cloud Backup Netapp oncommand Insight Netapp active Iq Unified Manager Netapp storage Replication Adapter For Clustered Data Ontap Netapp e-series Santricity Os Controller Debian debian Linux Netapp Netapp oncommand Performance Manager Netapp e-series Santricity Storage Manager Netapp virtual Storage Console Netapp element Software |
|
CPE | cpe:2.3:a:netapp:oncommand_unified_manager:-:*:*:*:*:7-mode:*:* cpe:2.3:a:phoenixcontact:fl_mguard_dm:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:e-series_santricity_storage_manager:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:storage_replication_adapter_for_clustered_data_ontap:*:*:*:*:*:windows:*:* cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:oncommand_unified_manager:*:*:*:*:*:vsphere:*:* cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:oncommand_performance_manager:-:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:netapp:element_software:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:virtual_storage_console:6.0:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:plug-in_for_symantec_netbackup:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:* cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* cpe:2.3:a:netapp:oncommand_balance:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:netapp:oncommand_shift:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:oncommand_unified_manager:*:*:*:*:*:windows:*:* cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap:6.0:*:*:*:*:*:*:* cpe:2.3:a:netapp:virtual_storage_console:*:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:oracle:*:* cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:sap:*:* |
13 May 2022, 14:57
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:oracle:jre:1.8.0:update_131:*:*:*:*:*:* |
cpe:2.3:a:oracle:jre:1.8.0:update131:*:*:*:*:*:* cpe:2.3:a:oracle:jre:1.7.0:update141:*:*:*:*:*:* |
Information
Published : 2017-08-08 15:29
Updated : 2023-12-10 12:15
NVD link : CVE-2017-10176
Mitre link : CVE-2017-10176
CVE.ORG link : CVE-2017-10176
JSON object : View
Products Affected
netapp
- element_software
- oncommand_balance
- cloud_backup
- oncommand_insight
- virtual_storage_console
- e-series_santricity_storage_manager
- active_iq_unified_manager
- oncommand_unified_manager
- vasa_provider_for_clustered_data_ontap
- snapmanager
- oncommand_shift
- steelstore_cloud_integrated_storage
- oncommand_performance_manager
- plug-in_for_symantec_netbackup
- storage_replication_adapter_for_clustered_data_ontap
- e-series_santricity_os_controller
oracle
- jre
- jdk
- jrockit
phoenixcontact
- fl_mguard_dm
debian
- debian_linux
CWE