Executive brief
A vulnerability exists in the Deployment component of Oracle Java SE, which is used to run Java applications and applets. An attacker could exploit this to gain unauthorized access to a limited amount of data on a user's computer. This issue primarily affects desktop users running untrusted Java content from the internet, such as sandboxed Web Start applications.
Technical details
This vulnerability affects the Deployment subcomponent of Oracle Java SE versions 6u131, 7u121, and 8u112. It is characterized as a difficult-to-exploit flaw that allows an unauthenticated attacker with network access via multiple protocols to compromise the Java sandbox. The impact is limited to unauthorized read access of a subset of Java SE accessible data (Confidentiality). The vulnerability specifically applies to client-side deployments running sandboxed Java Web Start applications or applets that execute untrusted code. It does not typically affect server-side deployments that run only trusted code. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Java SE 6u131, 7u121, 8u112
Timeline
- 2017-01-19: patched: Red Hat released security updates for affected Java versions.
- 2017-01-27: disclosed: Initial NVD publication.
References
- http://rhn.redhat.com/errata/RHSA-2017-0175.html
- http://rhn.redhat.com/errata/RHSA-2017-0176.html
- http://rhn.redhat.com/errata/RHSA-2017-0177.html
- http://rhn.redhat.com/errata/RHSA-2017-0263.html
- http://rhn.redhat.com/errata/RHSA-2017-0336.html
- http://rhn.redhat.com/errata/RHSA-2017-0337.html
- http://rhn.redhat.com/errata/RHSA-2017-0338.html