CVE-2017-10388
Description
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: Applies to the Java SE Kerberos client. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Risk Information
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in Java SE Development Kit 1.9.0 | Windows |
| Multiple vulnerabilities are fixed in Azul Zulu JDK 7 7.21 | Windows |
| Multiple vulnerabilities are fixed in Azul Zulu JDK 7 (x64) 7.21 | Windows |
| Multiple vulnerabilities are fixed in Azul Zulu JDK 8 (MSI) 8.25 | Windows |
| Multiple vulnerabilities are fixed in Azul Zulu JDK 8 (MSI) (x64) 8.25 | Windows |
| Multiple vulnerabilities are fixed in IBM WebSphere 8.0.0.15 | Windows |
| Multiple vulnerabilities are fixed in IBM WebSphere 7.0.0.45 | Windows |
| Multiple vulnerabilities are fixed in IBM WebSphere 8.5.5.13 | Windows |
| Multiple vulnerabilities are affected in Java SE Development Kit (x64) Java SE Development Kit 8 Update 144 (64-bit) | Windows |
| Multiple vulnerabilities are affected in Java SE Development Kit Java SE Development Kit 8 Update 144 (64-bit) | Windows |
| Multiple vulnerabilities are affected in Java SE Development Kit (x64) 8.0.1440 | Windows |
| Multiple vulnerabilities are affected in Java Runtime Environment 1.8 8.0.1440 | Windows |
| Multiple vulnerabilities are affected in Java Runtime Environment 1.8 (x64) 8.0.1440 | Windows |
| Multiple vulnerabilities are affected in Java SE Development Kit 7 (x64) 7.0.1510 | Windows |
| Multiple vulnerabilities are affected in Java SE Development Kit 7 (x86) 7.0.1510 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.0 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Controller 10.3.0 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Controller 10.3.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.5 | Windows |
| Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.6 | Windows |
| Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.7 | Windows |
| Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.8 | Windows |
| Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.9 | Windows |
| Java-1.7.0-openjdk security update (CESA-2017:3392) java-1.7.0-openjdk-1.7.0.161-2.6.12.0.el6_9.i686.rpm | Linux |
| Java-1.7.0-openjdk security update (CESA-2017:3392) java-1.7.0-openjdk-1.7.0.161-2.6.12.0.el6_9.x86_64.rpm | Linux |
| Java-1.7.0-openjdk security update (CESA-2017:3392) java-1.7.0-openjdk-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| Java-1.7.0-openjdk security update (CESA-2017:3392) java-1.7.0-openjdk-src-1.7.0.161-2.6.12.0.el6_9.i686.rpm | Linux |
| Java-1.7.0-openjdk security update (CESA-2017:3392) java-1.7.0-openjdk-src-1.7.0.161-2.6.12.0.el6_9.x86_64.rpm | Linux |
| Java-1.7.0-openjdk security update (CESA-2017:3392) java-1.7.0-openjdk-src-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| Java-1.7.0-openjdk security update (CESA-2017:3392) java-1.7.0-openjdk-demo-1.7.0.161-2.6.12.0.el6_9.i686.rpm | Linux |
| Java-1.7.0-openjdk security update (CESA-2017:3392) java-1.7.0-openjdk-demo-1.7.0.161-2.6.12.0.el6_9.x86_64.rpm | Linux |
| Java-1.7.0-openjdk security update (CESA-2017:3392) java-1.7.0-openjdk-demo-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| Java-1.7.0-openjdk security update (CESA-2017:3392) java-1.7.0-openjdk-devel-1.7.0.161-2.6.12.0.el6_9.i686.rpm | Linux |
| Java-1.7.0-openjdk security update (CESA-2017:3392) java-1.7.0-openjdk-devel-1.7.0.161-2.6.12.0.el6_9.x86_64.rpm | Linux |
| Java-1.7.0-openjdk security update (CESA-2017:3392) java-1.7.0-openjdk-devel-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| Java-1.7.0-openjdk security update (CESA-2017:3392) java-1.7.0-openjdk-javadoc-1.7.0.161-2.6.12.0.el6_9.noarch.rpm | Linux |
| Java-1.7.0-openjdk security update (CESA-2017:3392) java-1.7.0-openjdk-headless-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| Java-1.7.0-openjdk security update (CESA-2017:3392) java-1.7.0-openjdk-accessibility-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-1.7.0.161-2.6.12.0.el6_9.i686.rpm | Linux |
| (RHSA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-1.7.0.161-2.6.12.0.el6_9.x86_64.rpm | Linux |
| (RHSA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-accessibility-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-demo-1.7.0.161-2.6.12.0.el6_9.i686.rpm | Linux |
| (RHSA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-demo-1.7.0.161-2.6.12.0.el6_9.x86_64.rpm | Linux |
| (RHSA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-demo-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-devel-1.7.0.161-2.6.12.0.el6_9.i686.rpm | Linux |
| (RHSA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-devel-1.7.0.161-2.6.12.0.el6_9.x86_64.rpm | Linux |
| (RHSA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-devel-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-headless-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-javadoc-1.7.0.161-2.6.12.0.el6_9.noarch.rpm | Linux |
| (RHSA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-javadoc-1.7.0.161-2.6.12.0.el7_4.noarch.rpm | Linux |
| (RHSA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-src-1.7.0.161-2.6.12.0.el6_9.i686.rpm | Linux |
| (RHSA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-src-1.7.0.161-2.6.12.0.el6_9.x86_64.rpm | Linux |
| (RHSA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-src-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-1.8.0.151-1.b12.el6_9.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-1.8.0.151-1.b12.el6_9.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-1.8.0.151-1.b12.el7_4.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-1.8.0.151-1.b12.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-accessibility-1.8.0.151-1.b12.el7_4.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-accessibility-1.8.0.151-1.b12.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-accessibility-debug-1.8.0.151-1.b12.el7_4.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-accessibility-debug-1.8.0.151-1.b12.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-debug-1.8.0.151-1.b12.el6_9.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-debug-1.8.0.151-1.b12.el6_9.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-debug-1.8.0.151-1.b12.el7_4.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-debug-1.8.0.151-1.b12.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-demo-1.8.0.151-1.b12.el6_9.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-demo-1.8.0.151-1.b12.el6_9.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-demo-1.8.0.151-1.b12.el7_4.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-demo-1.8.0.151-1.b12.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-demo-debug-1.8.0.151-1.b12.el6_9.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-demo-debug-1.8.0.151-1.b12.el6_9.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-demo-debug-1.8.0.151-1.b12.el7_4.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-demo-debug-1.8.0.151-1.b12.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-devel-1.8.0.151-1.b12.el6_9.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-devel-1.8.0.151-1.b12.el6_9.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-devel-1.8.0.151-1.b12.el7_4.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-devel-1.8.0.151-1.b12.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-devel-debug-1.8.0.151-1.b12.el6_9.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-devel-debug-1.8.0.151-1.b12.el6_9.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-devel-debug-1.8.0.151-1.b12.el7_4.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-devel-debug-1.8.0.151-1.b12.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-headless-1.8.0.151-1.b12.el6_9.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-headless-1.8.0.151-1.b12.el6_9.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-headless-1.8.0.151-1.b12.el7_4.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-headless-1.8.0.151-1.b12.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-headless-debug-1.8.0.151-1.b12.el6_9.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-headless-debug-1.8.0.151-1.b12.el6_9.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-headless-debug-1.8.0.151-1.b12.el7_4.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-headless-debug-1.8.0.151-1.b12.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-javadoc-1.8.0.151-1.b12.el6_9.noarch.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-javadoc-1.8.0.151-1.b12.el7_4.noarch.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-javadoc-debug-1.8.0.151-1.b12.el6_9.noarch.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-javadoc-debug-1.8.0.151-1.b12.el7_4.noarch.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-javadoc-zip-1.8.0.151-1.b12.el7_4.noarch.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-javadoc-zip-debug-1.8.0.151-1.b12.el7_4.noarch.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-src-1.8.0.151-1.b12.el6_9.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-src-1.8.0.151-1.b12.el6_9.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-src-1.8.0.151-1.b12.el7_4.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-src-1.8.0.151-1.b12.el7_4.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-src-debug-1.8.0.151-1.b12.el6_9.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-src-debug-1.8.0.151-1.b12.el6_9.x86_64.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-src-debug-1.8.0.151-1.b12.el7_4.i686.rpm | Linux |
| (RHSA-2017:2998) java-1.8.0-openjdk security update java-1.8.0-openjdk-src-debug-1.8.0.151-1.b12.el7_4.x86_64.rpm | Linux |
| (CESA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| (CESA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-accessibility-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| (CESA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-demo-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| (CESA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-devel-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| (CESA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-headless-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| (CESA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-src-1.7.0.161-2.6.12.0.el7_4.x86_64.rpm | Linux |
| (CESA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-1.7.0.161-2.6.12.0.el6_9.i686.rpm | Linux |
| (CESA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-1.7.0.161-2.6.12.0.el6_9.x86_64.rpm | Linux |
| (CESA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-demo-1.7.0.161-2.6.12.0.el6_9.i686.rpm | Linux |
| (CESA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-demo-1.7.0.161-2.6.12.0.el6_9.x86_64.rpm | Linux |
| (CESA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-devel-1.7.0.161-2.6.12.0.el6_9.i686.rpm | Linux |
| (CESA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-devel-1.7.0.161-2.6.12.0.el6_9.x86_64.rpm | Linux |
| (CESA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-javadoc-1.7.0.161-2.6.12.0.el6_9.noarch.rpm | Linux |
| (CESA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-src-1.7.0.161-2.6.12.0.el6_9.i686.rpm | Linux |
| (CESA-2017:3392) Important: java-1.7.0-openjdk security and bug fix update java-1.7.0-openjdk-src-1.7.0.161-2.6.12.0.el6_9.x86_64.rpm | Linux |
| CVE-2017-10388 | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-333702 | Java SE Development Kit 8 Update 391 (32-bit) (8.0.3910.13) (JDK) (Manual Upload Required) |
| PATCH-344728 | Azul Zulu JDK 8 (MSI) (8.84.0.15) |
| PATCH-344692 | Azul Zulu JDK 8 (MSI) (x64) (8.84.0.15) |
| PATCH-349784 | Java SE Development Kit (x64) (8.0.4610.11) (Manual Upload Required) |
| PATCH-349781 | Java Runtime Environment 1.8 (8.0.4610.11) (Manual Upload Required) |
| PATCH-349782 | Java Runtime Environment 1.8 (x64) (8.0.4610.11) (Manual Upload Required) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234