CVE-2017-10118: High severity oracle java se 7 vulnerability
A covert timing channel flaw was found in the ECDSA implementation in the JCE component of OpenJDK. A remote attacker able to make a Java application generate ECDSA signatures on demand could possibly use this flaw to extract certain information about the used key via a timing side channel.
Other sources
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10118?
CVE-2017-10118 is classified as easily exploitable, allowing unauthenticated attackers with network access to exploit the vulnerability.
How do I fix CVE-2017-10118?
To fix CVE-2017-10118, update your Oracle Java SE or JRockit installations to the respective patched versions 7u141 or 8u131.
What versions are affected by CVE-2017-10118?
CVE-2017-10118 affects Oracle Java SE versions 7u141 and 8u131, as well as JRockit version R28.3.14.
Can CVE-2017-10118 affect applications using third-party libraries?
Yes, CVE-2017-10118 can affect any application that relies on the vulnerable versions of Oracle Java SE or JRockit.
Is there a workaround for CVE-2017-10118?
There are no specific workarounds for CVE-2017-10118, so upgrading to the latest secure versions is the recommended mitigation.