vulnerability

Huawei EulerOS: CVE-2017-10388: java-1.7.0-openjdk security update

Severity
5
CVSS
(AV:N/AC:H/Au:N/C:P/I:P/A:P)
Published
Oct 19, 2017
Added
Nov 30, 2017
Modified
Apr 25, 2025

Description

It was discovered that the Kerberos client implementation in the Libraries component of OpenJDK used the sname field from the plain text part rather than encrypted part of the KDC reply message. A man-in-the-middle attacker could possibly use this flaw to impersonate Kerberos services to Java applications acting as Kerberos clients.

Solutions

huawei-euleros-2_0_sp2-upgrade-java-1.7.0-openjdkhuawei-euleros-2_0_sp2-upgrade-java-1.7.0-openjdk-develhuawei-euleros-2_0_sp2-upgrade-java-1.7.0-openjdk-headless
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.