KLA11122
Multiple vulnerabilities in Oracle Java SE, Java SE Embedded and JRockit
Updated: 11/07/2017
CVSS
?
6.8
Detect date
?
10/17/2017
Severity
?
High
Description

Multiple serious vulnerabilities have been found in Oracle Java SE. Malicious users can exploit these vulnerabilities to cause denial of service and bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. An unspecified vulnerability in subcomponent Smart Card IO can be exploited remotely by unauthenticated attacker via multiple protocols to obtain sensitive information and to bypass security restrictions;
  2. An unspecified vulnerability in subcomponent Serialization can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  3. An unspecified vulnerability in subcomponent RMI (Remote Method Invocation) can be exploited remotely by unauthenticated attacker via multiple protocols to bypass security restrictions;
  4. An unspecified vulnerability in subcomponent Javadoc can be exploited remotely by unauthenticated attacker via multiple protocols to execute arbitrary code;
  5. An unspecified vulnerability in subcomponent Networking can be exploited remotely by unauthenticated attacker via HTTP to cause bypass security restrictions;
  6. An unspecified vulnerability in subcomponent Deployment can be exploited remotely by unauthenticated attacker via multiple protocols to bypass security restrictions;
  7. Unspecified vulnerabilities in subcomponent Server can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service or to bypass security restrictions;
  8. An unspecified vulnerability in subcomponent Server can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  9. An unspecified vulnerability in subcomponent Serialization can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  10. An unspecified vulnerability in subcomponent Hotspot can be exploited remotely by unauthenticated attacker via multiple protocols to bypass security restrictions;
  11. An unspecified vulnerability in subcomponent Serialization can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  12. An unspecified vulnerability in subcomponent Libraries can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  13. An unspecified vulnerability in subcomponent JAXP (Java API for XML Processing) can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  14. An unspecified vulnerability in subcomponent JAX-WS (The Java API for XML Web Services) can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  15. An unspecified vulnerability in subcomponent Networking can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  16. An unspecified vulnerability in subcomponent Security can be exploited remotely by unauthenticated attacker via multiple protocols to bypass security restrictions;
  17. An unspecified vulnerability in subcomponent Serialization can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  18. Unspecified vulnerabilities in subcomponent Server can be exploited remotely by unauthenticated attacker via HTTP protocols to bypass security restrictions;
  19. An unspecified vulnerability in subcomponent Libraries can be exploited remotely by unauthenticated attacker via multiple protocols to bypass security restrictions;

Technical details

Vulnerabilities (1), (4) and (6) are related to Java SE.

Vulnerabilities (2), (5), (9), (15) and (16) are related to Java SE, Java SE Embedded and JRockit

Vulnerabilities (3), (10), (12), (13), (14), (17) and (19) are related to Java SE and Java SE Embedded.

Vulnerabilities (7), (8) and (18) are related to Java Management Console.

Vulnerability (11) is related to Java SE and JRockit.

Affected products

Java SE 6 versions earlier than 6u161
Java SE 7 versions earlier than 7u151
Java SE 8 versions earlier than 8u151
Java SE Embedded versions earlier than 8u151
Java SE version 9
JRockit R28.3.15

Solution

Update to the latest version
Software downloads

Original advisories

Oracle Critical Patch Update Advisory – October 2017

Impacts
?
ACE 
[?]

SB 
[?]

DoS 
[?]
Related products
Oracle JRockit
Oracle Java JRE 1.8.x
Oracle Java JRE 1.7.x
Oracle Java JDK 1.8.x
Oracle Java JDK 1.7.x
CVE-IDS
?

CVE-2017-10388
CVE-2017-10386
CVE-2017-10380
CVE-2017-10357
CVE-2017-10356
CVE-2017-10355
CVE-2017-10350
CVE-2017-10349
CVE-2017-10348
CVE-2017-10347
CVE-2017-10346
CVE-2017-10345
CVE-2017-10342
CVE-2017-10341
CVE-2017-10309
CVE-2017-10295
CVE-2017-10293
CVE-2017-10285
CVE-2017-10281
CVE-2017-10274

Microsoft official advisories
Microsoft Security Update Guide
KB list

KB is Microsoft Knowledge Base article (In security case it corresponds Microsoft Security Advisory). KB is an atomic part of Microsoft security updates, which is detected by Microsoft Updater and can be installed or reverted. KB can contain not only programmatically updates and not only updates released by Microsoft.