Junglewise Threat Intelligence

CVE-2017-3259: Oracle Java SE information disclosure in Deployment component

CVE-2017-3259 · Severity: low · CVSS 3.7 · Published 2017-01-27

Technologies: Oracle Java SE. Vendors: Oracle.

Executive brief

A vulnerability exists in the Deployment component of Oracle Java SE, which is used to run Java applications and applets. An attacker could exploit this to gain unauthorized access to a limited amount of data on a user's computer. This issue primarily affects desktop users running untrusted Java content from the internet, such as sandboxed Web Start applications.

Technical details

This vulnerability affects the Deployment subcomponent of Oracle Java SE versions 6u131, 7u121, and 8u112. It is characterized as a difficult-to-exploit flaw that allows an unauthenticated attacker with network access via multiple protocols to compromise the Java sandbox. The impact is limited to unauthorized read access of a subset of Java SE accessible data (Confidentiality). The vulnerability specifically applies to client-side deployments running sandboxed Java Web Start applications or applets that execute untrusted code. It does not typically affect server-side deployments that run only trusted code. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Java SE 6u131, 7u121, 8u112

Timeline

  • 2017-01-19: patched: Red Hat released security updates for affected Java versions.
  • 2017-01-27: disclosed: Initial NVD publication.

References

Related threats