Arbitrary code execution in Oracle Java SE - CVE-2017-10125

 

Arbitrary code execution in Oracle Java SE - CVE-2017-10125

Published: September 5, 2017


Vulnerability identifier: #VU8080
CSH Severity: Medium
CVSS v4: 5.4 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-10125
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker with physical access to the system to execute arbitrary code on the target system.

The weakness exists due to unknown error. A remote attacker can execute arbitrary code with elevated privileges and compromise the vulnerable system.

Affected software

Oracle Java SE
IBM AIX
IBM Cognos Controller

How to mitigate CVE-2017-10125

Install update from vendor's website.


External References

Related Security Bulletins