CVE-2017-10115: High severity oracle java se 7 vulnerability
A covert timing channel flaw was found in the DSA implementation in the JCE component of OpenJDK. A remote attacker able to make a Java application generate DSA signatures on demand could possibly use this flaw to extract certain information about the used key via a timing side channel.
Note that the fix for this issue reverts the fix for CVE-2016-5548 (see bug 1413920) and uses different approach to implement blinding of the DSA operations.
Other sources
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10115?
CVE-2017-10115 has been rated as a high-severity vulnerability due to its potential for exploitation.
How do I fix CVE-2017-10115?
To fix CVE-2017-10115, upgrade to the latest version of Java SE, Java SE Embedded, or JRockit that are not affected by this vulnerability.
Which versions are affected by CVE-2017-10115?
CVE-2017-10115 affects Java SE version 6u151, 7u141, 8u131, Java SE Embedded version 8u131, and JRockit version R28.3.14.
Who can exploit CVE-2017-10115?
CVE-2017-10115 can be exploited by unauthenticated attackers over the network.
What component is impacted by CVE-2017-10115?
CVE-2017-10115 impacts the Java Cryptography Extension (JCE) component of Oracle Java SE.