First published: Tue Jan 17 2017(Updated: )
Oracle Java SE 8u121 fixes an unspecified vulnerability in the Java Mission Control component (<a href="https://access.redhat.com/security/cve/CVE-2017-3262">CVE-2017-3262</a>). Upstream has CVSS scored this issue as: 5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N External Reference: <a href="http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA">http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA</a>
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.8.0-oracle-1:1.8.0.121-1jpp.1.el6_8 | 1.8.0-oracle-1:1.8.0.121-1jpp.1.el6_8 |
redhat/java | <1.8.0-oracle-1:1.8.0.121-1jpp.1.el7_3 | 1.8.0-oracle-1:1.8.0.121-1jpp.1.el7_3 |
Oracle Java SE 7 | =1.8-update_112 | |
Oracle JRE | =1.8-update_112 | |
=1.8-update_112 | ||
=1.8-update_112 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3262 has a CVSS score of 5.3, indicating a medium severity vulnerability.
To fix CVE-2017-3262, update your Java installation to version 1.8.0_121 or later.
CVE-2017-3262 affects Oracle JDK and JRE versions prior to 1.8.0_121.
Yes, CVE-2017-3262 is classified as having a network attack vector, allowing potential remote exploitation.
CVE-2017-3262 specifically affects the Java Mission Control component in Oracle Java SE.