Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 7u141 and 8u131. Difficult to exploit vulnerability allows physical access to compromise Java SE. While the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: Applies to deployment of Java where the Java Auto Update is enabled. CVSS 3.0 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Project Subscriptions
| Vendors | Products |
|---|---|
|
Netapp
Subscribe
|
Active Iq Unified Manager
Subscribe
Cloud Backup
Subscribe
E-series Santricity Os Controller
Subscribe
E-series Santricity Storage Manager
Subscribe
Element Software
Subscribe
Oncommand Balance
Subscribe
Oncommand Insight
Subscribe
Oncommand Performance Manager
Subscribe
Oncommand Shift
Subscribe
Oncommand Unified Manager
Subscribe
Plug-in For Symantec Netbackup
Subscribe
Snapmanager
Subscribe
Steelstore Cloud Integrated Storage
Subscribe
Storage Replication Adapter For Clustered Data Ontap
Subscribe
Vasa Provider For Clustered Data Ontap
Subscribe
Virtual Storage Console
Subscribe
|
|
Oracle
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-1772 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 7u141 and 8u131. Difficult to exploit vulnerability allows physical access to compromise Java SE. While the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: Applies to deployment of Java where the Java Auto Update is enabled. CVSS 3.0 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 07 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2024-10-04T19:01:24.611Z
Reserved: 2017-06-21T00:00:00
Link: CVE-2017-10125
Updated: 2024-08-05T17:33:16.287Z
Status : Deferred
Published: 2017-08-08T15:29:04.087
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-10125
OpenCVE Enrichment
No data.
Weaknesses
EUVD