CVE-2017-10356
It was discovered that the Security component of OpenJDK generated weak password-based encryption keys used to protect private keys stored in key stores. This made it easier to perform password guessing attacks to decrypt stored keys if an attacker could gain access to a key store.
Find out more about CVE-2017-10356 from the MITRE CVE dictionary dictionary and NIST NVD.
CVSS v3 metrics
| CVSS3 Base Score | 6.2 |
|---|---|
| CVSS3 Base Metrics | CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| Attack Vector | Local |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Scope | Unchanged |
| Confidentiality | High |
| Integrity Impact | None |
| Availability Impact | None |
Red Hat Security Errata
| Platform | Errata | Release Date |
|---|---|---|
| Red Hat Enterprise Linux 7 (java-1.7.0-openjdk) | RHSA-2017:3392 | 2017-12-06 |
| Red Hat Enterprise Linux Supplementary (v. 7) (java-1.7.1-ibm) | RHSA-2017:3268 | 2017-11-28 |
| Red Hat Enterprise Linux 7 (java-1.8.0-openjdk) | RHSA-2017:2998 | 2017-10-20 |
| Red Hat Enterprise Linux 6 (java-1.8.0-openjdk) | RHSA-2017:2998 | 2017-10-20 |
| Oracle Java for Red Hat Enterprise Linux 7 (java-1.6.0-sun) | RHSA-2017:3047 | 2017-10-24 |
| Red Hat Enterprise Linux Supplementary (v. 7) (java-1.8.0-ibm) | RHSA-2017:3264 | 2017-11-27 |
| Oracle Java for Red Hat Enterprise Linux 6 (java-1.7.0-oracle) | RHSA-2017:3046 | 2017-10-24 |
| Oracle Java for Red Hat Enterprise Linux 7 (java-1.8.0-oracle) | RHSA-2017:2999 | 2017-10-23 |
| Oracle Java for Red Hat Enterprise Linux 6 (java-1.8.0-oracle) | RHSA-2017:2999 | 2017-10-23 |
| Oracle Java for Red Hat Enterprise Linux 7 (java-1.7.0-oracle) | RHSA-2017:3046 | 2017-10-24 |
| Red Hat Enterprise Linux Supplementary (v. 6) (java-1.7.1-ibm) | RHSA-2017:3268 | 2017-11-28 |
| Red Hat Enterprise Linux Supplementary (v. 6) (java-1.8.0-ibm) | RHSA-2017:3267 | 2017-11-28 |
| Red Hat Enterprise Linux 6 (java-1.7.0-openjdk) | RHSA-2017:3392 | 2017-12-06 |
| Oracle Java for Red Hat Enterprise Linux 6 (java-1.6.0-sun) | RHSA-2017:3047 | 2017-10-24 |
| Red Hat Satellite 5.8 (RHEL v.6) (java-1.8.0-ibm) | RHSA-2017:3453 | 2017-12-13 |
Affected Packages State
| Platform | Package | State |
|---|---|---|
| Red Hat Satellite 5 | java-1.7.1-ibm | Will not fix |
| Red Hat Enterprise Linux 6 | java-1.6.0-ibm | Will not fix |
