CVE-2017-10125

Description

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 7u141 and 8u131. Difficult to exploit vulnerability allows physical access to compromise Java SE. While the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: Applies to deployment of Java where the Java Auto Update is enabled. CVSS 3.0 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

Risk Information

Base Score
7.1
MODERATE
Vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.236

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Java jdk (x64) 8.0(x64)Windows
Multiple vulnerabilities affected in Java jdk 8.0Windows
Multiple vulnerabilities affected in Java jre (x64) 8.0(x64)Windows
Multiple vulnerabilities affected in Java jre 8.0Windows
Multiple vulnerabilities are affected in Java SE Development Kit 8 for Mac OS X Java SE Development Kit 8 Update 131Windows
Multiple vulnerabilities are affected in Java SE Development Kit (x64) Java SE Development Kit 8 Update 131Windows
Multiple vulnerabilities are affected in Java SE Development Kit Java SE Development Kit 8 Update 131Windows
Multiple vulnerabilities are affected in Java SE Development Kit (x64) 8.0.1310Windows
Multiple vulnerabilities are affected in Java Runtime Environment 1.8 8.0.1310Windows
Multiple vulnerabilities are affected in Java Runtime Environment 1.8 (x64) 8.0.1310Windows
Multiple vulnerabilities are affected in Java SE Development Kit 7 (x64) 7.0.1410Windows
Multiple vulnerabilities are affected in Java SE Development Kit 7 (x86) 7.0.1410Windows
Multiple Vulnerabilities are affected in Netapp Active Iq Unified Manager 2.3Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Insight 2.3Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.3.0Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Balance 2.3Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Shift 2.3Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0.8.0Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-333701Java SE Development Kit 8 Update 391 (64-bit) (8.0.3910.13) (JDK) (Manual Upload Required)
PATCH-333702Java SE Development Kit 8 Update 391 (32-bit) (8.0.3910.13) (JDK) (Manual Upload Required)
PATCH-349782Java Runtime Environment 1.8 (x64) (8.0.4610.11) (Manual Upload Required)
PATCH-306097Update for Java Runtime Environment (1.8.141)
PATCH-349784Java SE Development Kit (x64) (8.0.4610.11) (Manual Upload Required)
PATCH-349781Java Runtime Environment 1.8 (8.0.4610.11) (Manual Upload Required)
PATCH-349782Java Runtime Environment 1.8 (x64) (8.0.4610.11) (Manual Upload Required)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234