CVE-2017-10356: Medium severity oracle java se 7 vulnerability
It was discovered that key store implementations in the Security component of OpenJDK did not use sufficient number of iterations when generating password-based encryption keys used to protect private keys in key stores. This made it easier to perform password guessing attacks to decrypt stored keys if an attacker could gain access to a key store.
Other sources
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, Java SE Embedded, JRockit executes to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 6.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10356?
CVE-2017-10356 has a critical severity rating due to the potential for password guessing attacks against encrypted keys.
How do I fix CVE-2017-10356?
To fix CVE-2017-10356, upgrade to the latest version of the affected OpenJDK or Oracle JDK that addresses the vulnerability.
What software is affected by CVE-2017-10356?
CVE-2017-10356 affects specific versions of OpenJDK and Oracle JDK, including OpenJDK 8u382, Oracle JDK 6, 7, 8, and 9.
What types of attacks can be executed due to CVE-2017-10356?
CVE-2017-10356 can lead to password guessing attacks, allowing unauthorized access to sensitive private keys.
Is CVE-2017-10356 being actively exploited in the wild?
While there are no specific reports of active exploits for CVE-2017-10356, it is advisable to patch systems to mitigate potential risks.