CVE-2017-10388: High severity oracle java se 7 vulnerability
It was discovered that the Kerberos client implementation in the Libraries component of OpenJDK used the sname field from the plain text part rather than encrypted part of the KDC reply. A man-in-the-middle attacker could possibly use this flaw to impersonate Kerberos services to Java applications acting as Kerberos clients.
Other sources
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: Applies to the Java SE Kerberos client. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10388?
CVE-2017-10388 has been classified with high severity due to its potential for exploitation by man-in-the-middle attacks.
How do I fix CVE-2017-10388?
To remediate CVE-2017-10388, users should update to a patched version of OpenJDK or Oracle JDK that addresses the vulnerability.
What are the affected versions for CVE-2017-10388?
CVE-2017-10388 affects multiple versions of OpenJDK and Oracle JDK, including specific updates of versions 6, 7, and 8.
What type of attack does CVE-2017-10388 facilitate?
CVE-2017-10388 enables man-in-the-middle attacks that can allow an attacker to impersonate Kerberos services to Java applications.
Is CVE-2017-10388 specific to certain operating systems?
CVE-2017-10388 affects software across different operating systems, including Red Hat and Debian distributions.