Oracle Java SE 6 < Update 161 / 7 < Update 151 / 8 < Update 141 Multiple Vulnerabilities

Critical Nessus Network Monitor Plugin ID 700165

Synopsis

The remote host is missing a critical Oracle Java SE patch update.

Description

The version of Oracle Java SE installed on the remote host is prior to 6 Update 161, 7 Update 151, or 8 Update 141, and is therefore affected by a flaw that is triggered during object deserialization. This may allow a remote attacker to exhaust available memory and potentially cause a crash. (CVE-2017-10108, CVE-2017-10109)

These versions of Java SE are also affected by multiple vulerabilities in the following components :

2D (CVE-2017-10053), AWT (CVE-2017-10110), Deployment (CVE-2017-10105), Deployment (CVE-2017-10125), Hotspot (CVE-2017-10074, CVE-2017-10081), ImageIO (CVE-2017-10089), JAX-WS (CVE-2017-10243), JAXP (CVE-2017-10096, CVE-2017-10101), JCE (CVE-2017-10115, CVE-2017-10118, CVE-2017-10135), JavaFX (CVE-2017-10086, CVE-2017-10114), Libraries (CVE-2017-10087, CVE-2017-10090, CVE-2017-10111), RMI (CVE-2017-10102, CVE-2017-10107), Scripting (CVE-2017-10067, CVE-2017-10078), Security (CVE-2017-10116, CVE-2017-10176, CVE-2017-10193, CVE-2017-10198)

Solution

Upgrade to Java 1.8.0_141 or later. If version 1.8.x cannot be obtained, versions 1.7.0_151 and 1.6.0_161 have also been patched for these vulnerabilities.

See Also

http://www.nessus.org/u?aa1e4776

http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html#AppendixJAVA

Plugin Details

Severity: Critical

ID: 700165

Family: Web Clients

Published: 2017/07/26

Modified: 2018/09/16

Dependencies: 8892, 8895

Nessus ID: 101843, 101844

Risk Information

Risk Factor: Critical

CVSS v2.0

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

CVSS v3.0

Base Score: 9.8

Temporal Score: 9.4

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS3#E:X/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:oracle:java_se

Patch Publication Date: 2017/07/18

Vulnerability Publication Date: 2017/07/18

Reference Information

CVE: CVE-2017-1005, CVE-2017-1006, CVE-2017-1007, CVE-2017-1007, CVE-2017-1008, CVE-2017-1008, CVE-2017-1008, CVE-2017-1008, CVE-2017-1009, CVE-2017-1009, CVE-2017-1010, CVE-2017-1010, CVE-2017-1010, CVE-2017-1010, CVE-2017-1010, CVE-2017-1010, CVE-2017-1011, CVE-2017-1011, CVE-2017-1011, CVE-2017-1011, CVE-2017-1011, CVE-2017-1011, CVE-2017-1012, CVE-2017-1013, CVE-2017-1017, CVE-2017-1019, CVE-2017-1019, CVE-2017-1024

BID: 99643, 99659, 99662, 99670, 99674, 99703, 99706, 99707, 99712, 99719, 99726, 99731, 99734, 99752, 99756, 99774, 99782, 99788, 99809, 99818, 99827, 99839, 99842, 99846, 99847, 99851, 99853, 99854