Notified: March 16, 2017 Updated: April 03, 2017
Statement Date: March 16, 2017
Status
Unknown
Vendor Statement
The demonstrated code would not be able to be able to cause any harm for the reason that calling setAutoCommit( true ) requires a connection object which is not even initialized at that time (see lines 4067-4087 at: http://www.docjar.com/html/api/com/sun/rowset/JdbcRowSetImpl.java.html). Additionally, in our implementation all com.sun.* and java.* classes are excluded from deserialization.
Vendor Information
We are not aware of further vendor information regarding this vulnerability.