CVE-2017-10388: Debian Linux
High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: Applies to the Java SE Kerberos client. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Affected products
- Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
- Netapp Active Iq Unified Manager: from 7.3; from 9.5
- Netapp Cloud Backup: affected versions not specified
- Netapp E-Series Santricity Management Plug-Ins: affected versions not specified
- Netapp E-Series Santricity OS Controller: from 11.0, up to and including 11.70.1
- Netapp E-Series Santricity Storage Manager: affected versions not specified
- Netapp E-Series Santricity Web Services: affected versions not specified
- Netapp Element Software: affected versions not specified
- Netapp Oncommand Balance: affected versions not specified
- Netapp Oncommand Insight: affected versions not specified
- Netapp Oncommand Performance Manager: affected versions not specified
- Netapp Oncommand Shift: affected versions not specified
- Netapp Oncommand Unified Manager: up to and including 7.1; affected versions not specified
- Netapp Oncommand Workflow Automation: affected versions not specified
- Netapp Plug-In For Symantec Netbackup: affected versions not specified
- Netapp Snapmanager: affected versions not specified
- Netapp Steelstore Cloud Integrated Storage: affected versions not specified
- Netapp Storage Replication Adapter For Clustered Data Ontap: from 7.2
- Netapp Vasa Provider For Clustered Data Ontap: from 7.2; version 6.0 only
- Netapp Virtual Storage Console: from 7.2; version 6.0 only
- Oracle JDK: version 1.6.0 only; version 1.7.0 only; version 1.8.0 only; version 1.9.0 only
- Oracle JRE: version 1.6.0 only; version 1.7.0 only; version 1.8.0 only; version 1.9.0 only
- Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Eus: version 7.4 only; version 7.5 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
- and 4 more
Published 2017-10-19. Last modified 2026-06-17.