Junglewise Threat Intelligence

CVE-2017-3252: Oracle Java SE incorrect userDN extraction in JAAS LdapLoginModule

CVE-2017-3252 · Severity: medium · CVSS 5.8 · Published 2017-01-27

Technologies: Oracle Java SE, Oracle JRockit, Oracle Java SE Embedded. Vendors: Oracle.

Executive brief

A vulnerability in the Java Authentication and Authorization Service (JAAS) component of Oracle Java could allow an attacker to manipulate critical data. This issue affects various versions of Java SE and JRockit used in both desktop and server environments. If exploited, an attacker could unauthorizedly create, delete, or modify sensitive information, potentially impacting the integrity of the system and connected applications.

Technical details

A vulnerability exists in the LdapLoginModule of the JAAS subcomponent of Oracle Java SE. The flaw stems from incorrect user Distinguished Name (DN) extraction, which can be exploited by a low-privileged attacker with network access via multiple protocols. Exploitation is considered difficult as it requires human interaction from a person other than the attacker and involves a high degree of complexity. Successful exploitation allows for unauthorized creation, deletion, or modification of data accessible to the Java runtime. The vulnerability is reachable through sandboxed Java Web Start applications, applets, or by supplying malicious data to specific APIs, such as through a web service. Patching to Java SE 8u121, 7u131, or 6u141 (and equivalent versions for other branches) resolves the issue.

Affected products

  • Oracle Java SE 6u131, 7u121, 8u112
  • Oracle Java SE Embedded 8u111
  • Oracle JRockit R28.3.12

Timeline

  • 2017-01-19: patched: Oracle released the Critical Patch Update (CPU) addressing this issue.
  • 2017-01-27: disclosed: Public disclosure of the CVE.

References

Related threats