CVE-2017-10078
It was discovered that the Nashorn JavaScript engine in the Scripting component of OpenJDK could allow scripts to access Java APIs even when access to Java APIs was disabled. An untrusted JavaScript executed by Nashorn could use this flaw to bypass intended restrictions.
Find out more about CVE-2017-10078 from the MITRE CVE dictionary dictionary and NIST NVD.
CVSS v3 metrics
| CVSS3 Base Score | 8.1 |
|---|---|
| CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | Low |
| User Interaction | None |
| Scope | Unchanged |
| Confidentiality | High |
| Integrity Impact | High |
| Availability Impact | None |
Red Hat Security Errata
| Platform | Errata | Release Date |
|---|---|---|
| Red Hat Enterprise Linux Supplementary (v. 6) (java-1.8.0-ibm) | RHSA-2017:2469 | 2017-08-14 |
| Red Hat Enterprise Linux 6 (java-1.8.0-openjdk) | RHSA-2017:1789 | 2017-07-20 |
| Oracle Java for Red Hat Enterprise Linux 6 (java-1.8.0-oracle) | RHSA-2017:1790 | 2017-07-20 |
| Red Hat Enterprise Linux 7 (java-1.8.0-openjdk) | RHSA-2017:1789 | 2017-07-20 |
| Red Hat Enterprise Linux Supplementary (v. 7) (java-1.8.0-ibm) | RHSA-2017:2469 | 2017-08-14 |
| Red Hat Satellite 5.8 (RHEL v.6) (java-1.8.0-ibm) | RHSA-2017:3453 | 2017-12-13 |
| Oracle Java for Red Hat Enterprise Linux 7 (java-1.8.0-oracle) | RHSA-2017:1790 | 2017-07-20 |
Affected Packages State
| Platform | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 7 | java-1.7.0-openjdk | Not affected |
| Red Hat Enterprise Linux 6 | java-1.7.0-openjdk | Not affected |
