First published: Tue Aug 08 2017(Updated: )
Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Java Advanced Management Console. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java Advanced Management Console accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Java Advanced Management Console | =2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10117 is considered a high severity vulnerability due to its ease of exploitation by unauthenticated attackers.
To mitigate CVE-2017-10117, users should upgrade to a patched version of the Oracle Java Advanced Management Console.
CVE-2017-10117 affects Oracle Java Advanced Management Console version 2.6.
CVE-2017-10117 is an unauthenticated remote code execution vulnerability.
Yes, CVE-2017-10117 can be exploited remotely by an attacker with network access.