7.1

CVE-2017-10125

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 7u141 and 8u131. Difficult to exploit vulnerability allows physical access to compromise Java SE. While the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: Applies to deployment of Java where the Java Auto Update is enabled. CVSS 3.0 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Jdk Version 1.7.0 Update update141
Oracle ≫ Jdk Version 1.8.0 Update update131
Oracle ≫ Jre Version 1.7.0 Update update141
Oracle ≫ Jre Version 1.8.0 Update update131
Netapp ≫ Active Iq Unified Manager SwPlatform windows Version >= 7.3
Netapp ≫ Active Iq Unified Manager SwPlatform vmware_vsphere Version >= 9.5
Netapp ≫ Cloud Backup Version -
Netapp ≫ E-series Santricity Os Controller Version >= 11.0 <= 11.70.1
Netapp ≫ Element Software Version -
Netapp ≫ Oncommand Balance Version -
Netapp ≫ Oncommand Insight Version -
Netapp ≫ Oncommand Performance Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Oncommand Shift Version -
Netapp ≫ Oncommand Unified Manager SwPlatform vsphere Version <= 7.1
Netapp ≫ Oncommand Unified Manager SwPlatform windows Version <= 7.1
Netapp ≫ Oncommand Unified Manager Version - SwPlatform 7-mode
Netapp ≫ Snapmanager Version - SwPlatform oracle
Netapp ≫ Snapmanager Version - SwPlatform sap
Netapp ≫ Storage Replication Adapter For Clustered Data Ontap SwPlatform windows Version >= 7.2
Netapp ≫ Storage Replication Adapter For Clustered Data Ontap Version 9.6 SwPlatform vmware_vsphere
Netapp ≫ Virtual Storage Console SwPlatform vmware_vsphere Version >= 7.2
Netapp ≫ Virtual Storage Console Version 6.0 SwPlatform vmware_vsphere
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.454
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 0.5 6
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
NIST 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
Patch
Vendor Advisory
http://www.securitytracker.com/id/1038931
Broken Link
https://security.gentoo.org/glsa/201709-22
Third Party Advisory
https://security.netapp.com/advisory/ntap-20170720-0001/
Third Party Advisory
http://www.securityfocus.com/bid/99809
Broken Link