Information disclosure in JRockit and Oracle Java SE - CVE-2017-10198
Published: September 20, 2017
Vulnerability identifier: #VU8536
CSH Severity: Low
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-10198
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The weakness exists due to unknown error. A remote attacker can use multiple protocols to disclose important data on the target system
The weakness exists due to unknown error. A remote attacker can use multiple protocols to disclose important data on the target system
Affected software
JRockit
Oracle Java SE
mGuard Device Manager
Oracle Java SE
mGuard Device Manager
How to mitigate CVE-2017-10198
Install update form vendor's website.