Junglewise Threat Intelligence

CVE-2016-5552: Oracle Java SE incorrect URL parsing in URLStreamHandler

CVE-2016-5552 · Severity: medium · CVSS 5.3 · Published 2017-01-27

Technologies: Oracle Java SE, Oracle JRockit, Oracle Java SE Embedded. Vendors: Oracle.

Executive brief

A vulnerability in Oracle Java's networking component could allow an unauthorized person to modify or delete certain data. This affects both server-side applications and client-side tools like Java Web Start. An attacker could exploit this over a network without needing a username or password, potentially compromising the integrity of information processed by the Java environment.

Technical details

This vulnerability is classified as an incorrect URL parsing issue within the URLStreamHandler of the Networking subcomponent. It is easily exploitable by an unauthenticated attacker with network access via multiple protocols. The flaw can be triggered through sandboxed Java Web Start applications, sandboxed Java applets, or by supplying malicious data directly to affected APIs (e.g., via a web service). Successful exploitation allows an attacker to perform unauthorized updates, insertions, or deletions of data accessible to the Java runtime. The issue was addressed in the Oracle January 2017 Critical Patch Update.

Affected products

  • Oracle Java SE 6u131, 7u121, 8u112
  • Oracle Java SE Embedded 8u111
  • Oracle JRockit R28.3.12

Timeline

  • 2017-01-19: advisory: Red Hat published security advisories RHSA-2017:0175, RHSA-2017:0176, and RHSA-2017:0177.
  • 2017-01-27: disclosed: NVD published the CVE record.

References

Related threats