Vulnerability Details CVE-2017-10388
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: Applies to the Java SE Kerberos client. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.1%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.1
Products affected by CVE-2017-10388
-
cpe:2.3:a:netapp:active_iq_unified_manager:7.3
-
cpe:2.3:a:netapp:active_iq_unified_manager:9.10
-
cpe:2.3:a:netapp:active_iq_unified_manager:9.11p1
-
cpe:2.3:a:netapp:active_iq_unified_manager:9.5
-
cpe:2.3:a:netapp:active_iq_unified_manager:9.6
-
cpe:2.3:a:netapp:cloud_backup:-
-
cpe:2.3:a:netapp:e-series_santricity_management_plug-ins:-
-
cpe:2.3:a:netapp:e-series_santricity_os_controller:11.0
-
cpe:2.3:a:netapp:e-series_santricity_os_controller:11.0.0
-
cpe:2.3:a:netapp:e-series_santricity_os_controller:11.20
-
cpe:2.3:a:netapp:e-series_santricity_os_controller:11.25
-
cpe:2.3:a:netapp:e-series_santricity_os_controller:11.30
-
cpe:2.3:a:netapp:e-series_santricity_os_controller:11.30.5r3
-
cpe:2.3:a:netapp:e-series_santricity_os_controller:11.40
-
cpe:2.3:a:netapp:e-series_santricity_os_controller:11.40.3r2
-
cpe:2.3:a:netapp:e-series_santricity_os_controller:11.40.5
-
cpe:2.3:a:netapp:e-series_santricity_os_controller:11.50.1
-
cpe:2.3:a:netapp:e-series_santricity_os_controller:11.50.2
-
cpe:2.3:a:netapp:e-series_santricity_os_controller:11.60
-
cpe:2.3:a:netapp:e-series_santricity_os_controller:11.60.0
-
cpe:2.3:a:netapp:e-series_santricity_os_controller:11.60.1
-
cpe:2.3:a:netapp:e-series_santricity_os_controller:11.60.3
-
cpe:2.3:a:netapp:e-series_santricity_os_controller:11.70.1
-
cpe:2.3:a:netapp:e-series_santricity_storage_manager:-
-
cpe:2.3:a:netapp:e-series_santricity_web_services:-
-
cpe:2.3:a:netapp:element_software:-
-
cpe:2.3:a:netapp:oncommand_balance:-
-
cpe:2.3:a:netapp:oncommand_insight:-
-
cpe:2.3:a:netapp:oncommand_performance_manager:-
-
cpe:2.3:a:netapp:oncommand_shift:-
-
cpe:2.3:a:netapp:oncommand_unified_manager:-
-
cpe:2.3:a:netapp:oncommand_unified_manager:6.3
-
cpe:2.3:a:netapp:oncommand_unified_manager:6.4
-
cpe:2.3:a:netapp:oncommand_unified_manager:7.0
-
cpe:2.3:a:netapp:oncommand_unified_manager:7.1
-
cpe:2.3:a:netapp:oncommand_workflow_automation:-
-
cpe:2.3:a:netapp:plug-in_for_symantec_netbackup:-
-
cpe:2.3:a:netapp:snapmanager:-
-
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-
-
cpe:2.3:a:netapp:storage_replication_adapter_for_clustered_data_ontap:7.2
-
cpe:2.3:a:netapp:storage_replication_adapter_for_clustered_data_ontap:9.6
-
cpe:2.3:a:netapp:storage_replication_adapter_for_clustered_data_ontap:9.7
-
cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap:6.0
-
cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap:7.2
-
cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap:9.6
-
cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap:9.7
-
cpe:2.3:a:netapp:virtual_storage_console:6.0
-
cpe:2.3:a:netapp:virtual_storage_console:7.2
-
cpe:2.3:a:netapp:virtual_storage_console:9.6
-
cpe:2.3:a:netapp:virtual_storage_console:9.7
-
cpe:2.3:a:oracle:jdk:1.6.0
-
cpe:2.3:a:oracle:jdk:1.7.0
-
cpe:2.3:a:oracle:jdk:1.8.0
-
cpe:2.3:a:oracle:jdk:1.9.0
-
cpe:2.3:a:oracle:jre:1.6.0
-
cpe:2.3:a:oracle:jre:1.7.0
-
cpe:2.3:a:oracle:jre:1.8.0
-
cpe:2.3:a:oracle:jre:1.9.0
-
cpe:2.3:a:redhat:satellite:5.8
-
cpe:2.3:o:debian:debian_linux:7.0
-
cpe:2.3:o:debian:debian_linux:8.0
-
cpe:2.3:o:debian:debian_linux:9.0
-
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0
-
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0
-
cpe:2.3:o:redhat:enterprise_linux_eus:7.4
-
cpe:2.3:o:redhat:enterprise_linux_eus:7.5
-
cpe:2.3:o:redhat:enterprise_linux_eus:7.6
-
cpe:2.3:o:redhat:enterprise_linux_eus:7.7
-
cpe:2.3:o:redhat:enterprise_linux_server:6.0
-
cpe:2.3:o:redhat:enterprise_linux_server:7.0
-
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4
-
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6
-
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7
-
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.4
-
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6
-
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7
-
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0
-
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0