Executive brief
A vulnerability exists in Oracle Java Mission Control, a tool used for monitoring and managing Java applications. An attacker could potentially modify or delete certain data within the Java environment. While the impact is limited to data integrity, it could affect the reliability of application monitoring and management tasks.
Technical details
This vulnerability affects the Java Mission Control (JMC) component of Oracle Java SE version 8u112. It is characterized as a difficult-to-exploit flaw that allows an unauthenticated attacker with network access via multiple protocols to compromise the integrity of Java SE data. Specifically, successful exploitation can result in unauthorized update, insert, or delete access to some Java SE accessible data. The vulnerability was addressed in the Oracle January 2017 Critical Patch Update, with version 8u121 and later being unaffected.
Affected products
- Oracle Java SE 8u112
Timeline
- 2017-01-19: advisory: Red Hat security advisory issued
- 2017-01-27: disclosed: NVD publication date
References
- http://rhn.redhat.com/errata/RHSA-2017-0175.html
- http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html
- http://www.securityfocus.com/bid/95581
- http://www.securitytracker.com/id/1037637
- https://security.gentoo.org/glsa/201701-65
- https://security.netapp.com/advisory/ntap-20170119-0001/