CVE-2017-3262: Medium severity Oracle JDK vulnerability
Oracle Java SE 8u121 fixes an unspecified vulnerability in the Java Mission Control component (CVE-2017-3262). Upstream has CVSS scored this issue as: 5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA
Other sources
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control). The supported version that is affected is Java SE: 8u112. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. Note: Applies to Java Mission Control Installation. CVSS v3.0 Base Score 5.3 (Confidentiality impacts).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-oracle-1:1.8.0.121-1jpp.1.el6_8 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-oracle-1:1.8.0.121-1jpp.1.el7_3 - Upgrade
Upgrade
Oracle Java SE (Java Mission Control)to a version that resolves this vulnerability.Fixed in 8u121 - Compensating control
If using Java Mission Control, treat it as exposed via multiple network-accessible protocols because the vulnerability is remotely exploitable by unauthenticated attackers.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3262?
CVE-2017-3262 has a CVSS score of 5.3, indicating a medium severity vulnerability.
How do I fix CVE-2017-3262?
To fix CVE-2017-3262, update your Java installation to version 1.8.0_121 or later.
Which versions of Java are affected by CVE-2017-3262?
CVE-2017-3262 affects Oracle JDK and JRE versions prior to 1.8.0_121.
Is CVE-2017-3262 a remote vulnerability?
Yes, CVE-2017-3262 is classified as having a network attack vector, allowing potential remote exploitation.
What components are involved in CVE-2017-3262?
CVE-2017-3262 specifically affects the Java Mission Control component in Oracle Java SE.