4.3

CVE-2017-3533

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via FTP to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Jdk Version 1.6.0 Update update141
Oracle ≫ Jdk Version 1.7.0 Update update131
Oracle ≫ Jdk Version 1.8.0 Update update121
Oracle ≫ Jre Version 1.6.0 Update update141
Oracle ≫ Jre Version 1.7.0 Update update_131
Oracle ≫ Jre Version 1.8.0 Update update_121
Oracle ≫ Jrockit Version r28.3.13
Redhat ≫ Satellite Version 5.8
Redhat ≫ Icedtea Version < 3.4.0
Debian ≫ Debian Linux Version 8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.58% 0.832
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.7 2.2 1.4
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html
Patch
Vendor Advisory
https://security.gentoo.org/glsa/201707-01
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3453
Third Party Advisory
http://www.debian.org/security/2017/dsa-3858
Third Party Advisory
http://www.securitytracker.com/id/1038286
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHSA-2017:1108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1109
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1117
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1118
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1119
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1204
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1220
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1221
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1222
Third Party Advisory
https://security.gentoo.org/glsa/201705-03
Third Party Advisory
http://www.securityfocus.com/bid/97740
Third Party Advisory
VDB Entry