Executive brief
A vulnerability exists in Oracle Java Mission Control, a tool used for monitoring and managing Java applications. An unauthenticated attacker could exploit this flaw over a network to gain unauthorized access to a specific subset of data within the Java environment. This could lead to the exposure of sensitive application information or configuration details.
Technical details
This vulnerability affects the Java Mission Control (JMC) component of Oracle Java SE version 8u112. It is classified as an information disclosure flaw that is easily exploitable by an unauthenticated attacker with network access via multiple protocols. The root cause is unspecified by the vendor but relates to improper access control within the JMC installation. Successful exploitation allows the attacker to read a subset of data accessible to the Java SE environment. The issue was addressed in the Oracle January 2017 Critical Patch Update by upgrading to version 8u121.
Affected products
- Oracle Java SE 8u112
Timeline
- 2017-01-17: advisory: Oracle January 2017 Critical Patch Update released
- 2017-01-19: patched: Red Hat released security updates for java-1.8.0-oracle
- 2017-01-27: disclosed: NVD publication date
References
- http://rhn.redhat.com/errata/RHSA-2017-0175.html
- http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html
- http://www.securityfocus.com/bid/95578
- http://www.securitytracker.com/id/1037637
- https://security.gentoo.org/glsa/201701-65
- https://security.netapp.com/advisory/ntap-20170119-0001/