CVE-2017-10125

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 7u141 and 8u131. Difficult to exploit vulnerability allows physical access to compromise Java SE. While the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: Applies to deployment of Java where the Java Auto Update is enabled. CVSS 3.0 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

References

http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html

http://www.securityfocus.com/bid/99809

http://www.securitytracker.com/id/1038931

https://security.gentoo.org/glsa/201709-22

https://security.netapp.com/advisory/ntap-20170720-0001/

Details

Source: MITRE

Published: 2017-08-08

Updated: 2020-09-08

Risk Information

CVSS v2

Base Score: 4.4

Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 3.4

Severity: MEDIUM

CVSS v3

Base Score: 7.1

Vector: CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Impact Score: 6

Exploitability Score: 0.5

Severity: HIGH

Tenable Plugins

View all (15 total)

IDNameProductFamilySeverity
121719Photon OS 1.0: Openjre PHSA-2017-0026NessusPhotonOS Local Security Checks
critical
121718Photon OS 1.0: Openjdk PHSA-2017-0026NessusPhotonOS Local Security Checks
critical
111875Photon OS 1.0: Openjdk / Openjre / Pycrypto / Python3 PHSA-2017-0026 (deprecated)NessusPhotonOS Local Security Checks
critical
105714openSUSE Security Update : java-1_7_0-openjdk (openSUSE-2018-14)NessusSuSE Local Security Checks
critical
105538SUSE SLED12 / SLES12 Security Update : java-1_7_0-openjdk (SUSE-SU-2018:0005-1)NessusSuSE Local Security Checks
critical
103450GLSA-201709-22 : Oracle JDK/JRE, IcedTea: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
103191AIX Java Advisory : java_july2017_advisory.asc (July 2017 CPU)NessusAIX Local Security Checks
critical
102837SUSE SLES11 Security Update : java-1_7_1-ibm (SUSE-SU-2017:2281-1)NessusSuSE Local Security Checks
critical
102836SUSE SLES12 Security Update : java-1_7_1-ibm (SUSE-SU-2017:2280-1)NessusSuSE Local Security Checks
critical
102801SUSE SLES12 Security Update : java-1_8_0-ibm (SUSE-SU-2017:2263-1)NessusSuSE Local Security Checks
critical
102621openSUSE Security Update : java-1_8_0-openjdk (openSUSE-2017-954)NessusSuSE Local Security Checks
critical
102541SUSE SLED12 / SLES12 Security Update : java-1_8_0-openjdk (SUSE-SU-2017:2175-1)NessusSuSE Local Security Checks
critical
700165Oracle Java SE 6 < Update 161 / 7 < Update 151 / 8 < Update 141 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
critical
101844Oracle Java SE Multiple Vulnerabilities (July 2017 CPU) (Unix)NessusMisc.
critical
101843Oracle Java SE Multiple Vulnerabilities (July 2017 CPU)NessusWindows
critical