CVE-2017-10388

high
Published 2017-10-19 ยท Modified 2026-05-13
CVSS v3
7.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
7.5

Description

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: Applies to the Java SE Kerberos client. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).

Predictions

Exploit likelihood
83%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

redhat Red Hat Affected 6 releases
VersionStatusFixed in
7.7 Affected โ€”
7.6 Affected โ€”
7.5 Affected โ€”
7.4 Affected โ€”
7.0 Affected โ€”
6.0 Affected โ€”
suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
debian Debian Mixed 4 releases
VersionStatusFixed in
sid Fixed 8u151-b12-1
9.0 Affected โ€”
8.0 Affected โ€”
7.0 Affected โ€”

Application impact

VendorProductVersionsFixed
oracle oraclejdk1.6.0
oracle oraclejdk1.7.0
oracle oraclejdk1.8.0
oracle oraclejdk1.9.0
oracle oraclejre1.6.0
oracle oraclejre1.7.0
oracle oraclejre1.8.0
oracle oraclejre1.9.0
redhat redhatsatellite5.8
netappactive_iq_unified_manager{"startIncluding":"7.3"}
netappcloud_backup-
netappe-series_santricity_management_plug-ins-
netappe-series_santricity_os_controller{"startIncluding":"11.0","endIncluding":"11.70.1"}
netappe-series_santricity_storage_manager-
netappe-series_santricity_web_services-
netappelement_software-
netapponcommand_balance-
netapponcommand_insight-
netapponcommand_performance_manager-
netapponcommand_shift-
netapponcommand_unified_manager{"endIncluding":"7.1"}
netapponcommand_unified_manager-
netapponcommand_workflow_automation-
netappplug-in_for_symantec_netbackup-
netappsnapmanager-
netappsteelstore_cloud_integrated_storage-
netappstorage_replication_adapter_for_clustered_data_ontap{"startIncluding":"7.2"}
netappvasa_provider_for_clustered_data_ontap{"startIncluding":"7.2"}
netappvasa_provider_for_clustered_data_ontap6.0
netappvirtual_storage_console{"startIncluding":"7.2"}
netappvirtual_storage_console6.0

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.