CVE-2017-10193: Low severity oracle java se 7 vulnerability
A flaw was found in the DisabledAlgorithmConstraints class in the Security component of OpenJDK. A key size constrained could not have been checked correctly in certain cases, causing weak key to be accepted. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions.
Other sources
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10193?
CVE-2017-10193 is classified as a difficult-to-exploit vulnerability with a high potential impact.
How do I fix CVE-2017-10193?
To mitigate CVE-2017-10193, upgrade to a version of Oracle Java SE that is not affected, specifically versions beyond the vulnerable ones.
Which versions are affected by CVE-2017-10193?
CVE-2017-10193 affects Oracle Java SE versions 6u151, 7u141, and 8u131, along with Java SE Embedded version 8u131.
Can CVE-2017-10193 be exploited remotely?
Yes, CVE-2017-10193 allows an unauthenticated attacker with network access to potentially exploit this vulnerability.
Is there a specific vendor for CVE-2017-10193?
CVE-2017-10193 is associated with Oracle Java SE and products relying on this software.