CVE-2017-10121 is a vulnerability in Oracle Java Advanced Management Console version 2.6, specifically affecting its Server subcomponent. This easily exploitable vulnerability allows an unauthenticated attacker to compromise the console via HTTP, requiring user interaction. Successful exploitation can lead to unauthorized modification or deletion of some accessible data, as well as unauthorized read access to a subset of data. The vulnerability has a CVSS 3.0 Base Score of 6.1 (Medium), indicating a low confidentiality and integrity impact. Its attack vector is network-based with low attack complexity, but requires user interaction. While the vulnerability is present in the Java Advanced Management Console, successful attacks may impact additional products. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The CVE has received minimal community discussion and media coverage, suggesting a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6CPE matchmatch criteria | cpe:2.3:a:oracle:java_advanced_management_console:2.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.