5.3

CVE-2017-10357

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OracleJdk Version1.6.0 Updateupdate161
OracleJdk Version1.7.0 Updateupdate151
OracleJdk Version1.8.0 Updateupdate144
OracleJdk Version1.9.0
OracleJre Version1.6.0 Updateupdate161
OracleJre Version1.7.0 Updateupdate151
OracleJre Version1.8.0 Updateupdate144
OracleJre Version1.9.0
RedhatSatellite Version5.8
RedhatEnterprise Linux Eus Version7.4
RedhatEnterprise Linux Eus Version7.5
RedhatEnterprise Linux Eus Version7.6
RedhatEnterprise Linux Eus Version7.7
NetappActive Iq Unified Manager SwPlatformwindows Version >= 7.3
NetappActive Iq Unified Manager SwPlatformvmware_vsphere Version >= 9.5
NetappCloud Backup Version-
NetappE-series Santricity Management Plug-ins Version- SwPlatformvmware_vcenter
NetappE-series Santricity Os Controller Version >= 11.0 <= 11.70.1
NetappE-series Santricity Web Services Version- SwPlatformweb_services_proxy
NetappElement Software Version-
NetappOncommand Balance Version-
NetappOncommand Insight Version-
NetappOncommand Performance Manager Version- SwPlatformvmware_vsphere
NetappOncommand Shift Version-
NetappOncommand Unified Manager SwPlatformvsphere Version <= 7.1
NetappOncommand Unified Manager SwPlatformwindows Version <= 7.1
NetappOncommand Unified Manager Version- SwPlatform7-mode
NetappSnapmanager Version- SwPlatformoracle
NetappSnapmanager Version- SwPlatformsap
NetappStorage Replication Adapter For Clustered Data Ontap SwPlatformvmware_vsphere Version >= 7.2
NetappStorage Replication Adapter For Clustered Data Ontap SwPlatformwindows Version >= 7.2
NetappVirtual Storage Console SwPlatformvmware_vsphere Version >= 7.2
NetappVirtual Storage Console Version6.0 SwPlatformvmware_vsphere
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.73% 0.719
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P