Lucene search

K
kasperskyKaspersky LabKLA11006
HistoryApr 24, 2017 - 12:00 a.m.

KLA11006 Multiple vulnerabilities in Oracle Java SE

2017-04-2400:00:00
Kaspersky Lab
threats.kaspersky.com
256

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

8.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.4%

Multiple serious vulnerabilities have been found in Oracle Java SE components. Malicious users can exploit these vulnerabilities possibly to obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. An unspecified vulnerability in subcomponent JCE (Java Cryptography Extension) can be exploited remotely by an unauthenticated attacker with logon to the infrastructure possibly to obtain sensitive information;
  2. An unspecified vulnerability in subcomponent AWT (Abstract Windows Toolkit) can be exploited remotely by an unauthenticated attacker via multiple protocols possibly to obtain sensitive information.

Technical details

All vulnerabilities are applicable to Java deployments (usually in clients, which run sandboxed Java Applets or sandboxed Jawa Web Start Applications and rely on the Java sandbox security) that use untrusted code (for example, code from the Internet). Java deployments running trusted code (for example, code installed by an administrator) are not vulnerable.

Successful exploits of all vulnerabilities require user interaction (with not the same person as the unauthenticated attacker).

Vulnerability (1) is related to Java SE, Java SE Embedded and JRockit components.

Vulnerability (2) is related only to Java SE.

Original advisories

Oracle Critical Patch Update Advisory

Related products

Oracle-Java-JRE-1.7.x

Oracle-Java-JRE-1.8.x

Oracle-JRockit

CVE list

CVE-2017-3511 warning

CVE-2017-3512 high

Solution

Update to the latest version

Get Java SE

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

Affected Products

  • Oracle Java SE 7u131Oracle Java SE 8u121Oracle Java SE Embedded 8u121Oracle JRockit R28.3.13

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

8.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.4%