Improper access control in Oracle Java SE - CVE-2017-10309
Published: October 18, 2017 / Updated: October 27, 2020
Vulnerability identifier: #VU8868
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-10309
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to access potentially sensitive information and cause DoS condition.
The weakness exists due to a flaw in the Deployment component. A remote attacker can partially read and modify arbitrary files and cause partial denial of service on the target system.
The weakness exists due to a flaw in the Deployment component. A remote attacker can partially read and modify arbitrary files and cause partial denial of service on the target system.
Affected software
Oracle Java SE
Gentoo Linux
IBM AIX
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
SUSE Linux
Red Hat Satellite
java-1.8.0-oracle (Red Hat package)
java-1.8.0-oracle-devel (Red Hat package)
java-1.8.0-oracle-javafx (Red Hat package)
java-1.8.0-oracle-jdbc (Red Hat package)
java-1.8.0-oracle-plugin (Red Hat package)
java-1.8.0-oracle-src (Red Hat package)
Gentoo Linux
IBM AIX
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
SUSE Linux
Red Hat Satellite
java-1.8.0-oracle (Red Hat package)
java-1.8.0-oracle-devel (Red Hat package)
java-1.8.0-oracle-javafx (Red Hat package)
java-1.8.0-oracle-jdbc (Red Hat package)
java-1.8.0-oracle-plugin (Red Hat package)
java-1.8.0-oracle-src (Red Hat package)
How to mitigate CVE-2017-10309
The vulnerability is addressed in the following version: 8u151.
java-1.8.0-oracle (Red Hat package) - addressed in versions 1.8.0.151-1jpp.1.el6, 1.8.0.151-1jpp.5.el7
java-1.8.0-oracle-devel (Red Hat package) - addressed in versions 1.8.0.151-1jpp.1.el6, 1.8.0.151-1jpp.5.el7
java-1.8.0-oracle-javafx (Red Hat package) - addressed in versions 1.8.0.151-1jpp.1.el6, 1.8.0.151-1jpp.5.el7
java-1.8.0-oracle-jdbc (Red Hat package) - addressed in versions 1.8.0.151-1jpp.1.el6, 1.8.0.151-1jpp.5.el7
java-1.8.0-oracle-plugin (Red Hat package) - addressed in versions 1.8.0.151-1jpp.1.el6, 1.8.0.151-1jpp.5.el7
java-1.8.0-oracle-src (Red Hat package) - addressed in versions 1.8.0.151-1jpp.1.el6, 1.8.0.151-1jpp.5.el7
java-1.8.0-oracle-devel (Red Hat package) - addressed in versions 1.8.0.151-1jpp.1.el6, 1.8.0.151-1jpp.5.el7
java-1.8.0-oracle-javafx (Red Hat package) - addressed in versions 1.8.0.151-1jpp.1.el6, 1.8.0.151-1jpp.5.el7
java-1.8.0-oracle-jdbc (Red Hat package) - addressed in versions 1.8.0.151-1jpp.1.el6, 1.8.0.151-1jpp.5.el7
java-1.8.0-oracle-plugin (Red Hat package) - addressed in versions 1.8.0.151-1jpp.1.el6, 1.8.0.151-1jpp.5.el7
java-1.8.0-oracle-src (Red Hat package) - addressed in versions 1.8.0.151-1jpp.1.el6, 1.8.0.151-1jpp.5.el7
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in Oracle Java SE
- Gentoo update for Oracle JDK/JRE
- Multiple vulnerabilities in IBM AIX
- SUSE Linux update for java-1_8_0-ibm
- Red Hat update for java-1.8.0-ibm
- Red Hat update for java-1.8.0-ibm
- Red Hat update for java-1.8.0-ibm
- Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7 update for java-1.8.0-oracle