CVE-2017-10176: High severity oracle java se 7 vulnerability
It was discovered that the Elliptic Curve (EC) cryptography implementation in the Security component of OpenJDK did not perform computations for certain points correctly. An attacker able to interact with a Java application using EC cryptography could possibly use this flaw to obtain information about the used key.
Other sources
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10176?
CVE-2017-10176 is classified as a critical vulnerability due to its ease of exploitation and potential impact on affected systems.
How do I fix CVE-2017-10176?
To remediate CVE-2017-10176, upgrade to the latest versions of Oracle Java SE, Java SE Embedded, or JRockit as advised by Oracle.
Which versions are affected by CVE-2017-10176?
CVE-2017-10176 affects Java SE 7u141, Java SE 8u131, Java SE Embedded 8u131, and JRockit R28.3.14.
Can CVE-2017-10176 be exploited remotely?
Yes, CVE-2017-10176 can be easily exploited by an unauthenticated attacker over the network.
What components of Oracle Java SE does CVE-2017-10176 impact?
CVE-2017-10176 impacts the Security component of Oracle Java SE, Java SE Embedded, and JRockit.