F5 Networks BIG-IP : Oracle Java SE vulnerability (K15217245)
Medium Nessus Plugin ID 118632
SynopsisThe remote device is missing a vendor-supplied security patch.
DescriptionVulnerability in the Java SE, Java SE Embedded, JRockit component of
Oracle Java SE (subcomponent: Serialization). Supported versions that
are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE
Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability
allows unauthenticated attacker with network access via multiple
protocols to compromise Java SE, Java SE Embedded, JRockit. Successful
attacks of this vulnerability can result in unauthorized ability to
cause a partial denial of service (partial DOS) of Java SE, Java SE
Embedded, JRockit. Note: Applies to client and server deployment of
Java. This vulnerability can be exploited through sandboxed Java Web
Start applications and sandboxed Java applets. It can also be
exploited by supplying data to APIs in the specified Component without
using sandboxed Java Web Start applications or sandboxed Java applets,
such as through a web service. CVSS 3.0 Base Score 5.3 (Availability
impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
BIG-IP / BIG-IQ / F5 iWorkflow / Enterprise Manager / Traffix SDC
An attacker may cause a partial denial of service (DoS) to the
affected Java component when the vulnerability is exploited.
There is no impact; thisF5 product is not affected by this
SolutionUpgrade to one of the non-vulnerable versions listed in the F5