Lucene search

K
nvd[email protected]NVD:CVE-2020-2803
HistoryApr 15, 2020 - 2:15 p.m.

CVE-2020-2803

2020-04-1514:15:28
web.nvd.nist.gov
7

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

CVSS3

8.3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.002

Percentile

52.6%

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

Affected configurations

Nvd
Node
oraclejdkMatch1.7.0update251
OR
oraclejdkMatch1.8.0update241
OR
oraclejdkMatch11.0.6
OR
oraclejdkMatch14.0.0
OR
oraclejreMatch1.7.0update_251
OR
oraclejreMatch1.8.0update_241
OR
oraclejreMatch11.0.6
OR
oraclejreMatch14.0.0
Node
oracleopenjdkRange1111.0.6
OR
oracleopenjdkRange1313.0.2
OR
oracleopenjdkMatch7-
OR
oracleopenjdkMatch7update1
OR
oracleopenjdkMatch7update10
OR
oracleopenjdkMatch7update101
OR
oracleopenjdkMatch7update11
OR
oracleopenjdkMatch7update111
OR
oracleopenjdkMatch7update121
OR
oracleopenjdkMatch7update13
OR
oracleopenjdkMatch7update131
OR
oracleopenjdkMatch7update141
OR
oracleopenjdkMatch7update15
OR
oracleopenjdkMatch7update151
OR
oracleopenjdkMatch7update161
OR
oracleopenjdkMatch7update17
OR
oracleopenjdkMatch7update171
OR
oracleopenjdkMatch7update181
OR
oracleopenjdkMatch7update191
OR
oracleopenjdkMatch7update2
OR
oracleopenjdkMatch7update201
OR
oracleopenjdkMatch7update21
OR
oracleopenjdkMatch7update211
OR
oracleopenjdkMatch7update221
OR
oracleopenjdkMatch7update231
OR
oracleopenjdkMatch7update241
OR
oracleopenjdkMatch7update25
OR
oracleopenjdkMatch7update251
OR
oracleopenjdkMatch7update3
OR
oracleopenjdkMatch7update4
OR
oracleopenjdkMatch7update40
OR
oracleopenjdkMatch7update45
OR
oracleopenjdkMatch7update5
OR
oracleopenjdkMatch7update51
OR
oracleopenjdkMatch7update55
OR
oracleopenjdkMatch7update6
OR
oracleopenjdkMatch7update60
OR
oracleopenjdkMatch7update65
OR
oracleopenjdkMatch7update67
OR
oracleopenjdkMatch7update7
OR
oracleopenjdkMatch7update72
OR
oracleopenjdkMatch7update76
OR
oracleopenjdkMatch7update80
OR
oracleopenjdkMatch7update85
OR
oracleopenjdkMatch7update9
OR
oracleopenjdkMatch7update91
OR
oracleopenjdkMatch7update95
OR
oracleopenjdkMatch7update97
OR
oracleopenjdkMatch7update99
OR
oracleopenjdkMatch8-
OR
oracleopenjdkMatch8update101
OR
oracleopenjdkMatch8update102
OR
oracleopenjdkMatch8update11
OR
oracleopenjdkMatch8update111
OR
oracleopenjdkMatch8update112
OR
oracleopenjdkMatch8update121
OR
oracleopenjdkMatch8update131
OR
oracleopenjdkMatch8update141
OR
oracleopenjdkMatch8update151
OR
oracleopenjdkMatch8update152
OR
oracleopenjdkMatch8update161
OR
oracleopenjdkMatch8update162
OR
oracleopenjdkMatch8update171
OR
oracleopenjdkMatch8update172
OR
oracleopenjdkMatch8update181
OR
oracleopenjdkMatch8update191
OR
oracleopenjdkMatch8update192
OR
oracleopenjdkMatch8update20
OR
oracleopenjdkMatch8update201
OR
oracleopenjdkMatch8update202
OR
oracleopenjdkMatch8update211
OR
oracleopenjdkMatch8update212
OR
oracleopenjdkMatch8update221
OR
oracleopenjdkMatch8update231
OR
oracleopenjdkMatch8update241
OR
oracleopenjdkMatch8update25
OR
oracleopenjdkMatch8update31
OR
oracleopenjdkMatch8update40
OR
oracleopenjdkMatch8update45
OR
oracleopenjdkMatch8update5
OR
oracleopenjdkMatch8update51
OR
oracleopenjdkMatch8update60
OR
oracleopenjdkMatch8update65
OR
oracleopenjdkMatch8update66
OR
oracleopenjdkMatch8update71
OR
oracleopenjdkMatch8update72
OR
oracleopenjdkMatch8update73
OR
oracleopenjdkMatch8update74
OR
oracleopenjdkMatch8update77
OR
oracleopenjdkMatch8update91
OR
oracleopenjdkMatch8update92
OR
oracleopenjdkMatch14
Node
netapp7-mode_transition_toolMatch-
OR
netappactive_iq_unified_managerRange7.3windows
OR
netappactive_iq_unified_managerRange9.5vsphere
OR
netappcloud_backupMatch-
OR
netappe-series_performance_analyzerMatch-
OR
netappe-series_santricity_os_controllerRange11.0.011.70.2
OR
netappe-series_santricity_web_servicesMatch-web_services_proxy
OR
netapponcommand_insightMatch-
OR
netapponcommand_workflow_automationMatch-
OR
netappplug-in_for_symantec_netbackupMatch-
OR
netappsantricity_unified_managerMatch-
OR
netappsnapmanagerMatch-sap
OR
netappsnapmanagerMatch--oracle
OR
netappsteelstore_cloud_integrated_storageMatch-
OR
netappstoragegridRange9.0.09.0.4
OR
netappstoragegridMatch-
Node
debiandebian_linuxMatch8.0
OR
debiandebian_linuxMatch9.0
OR
debiandebian_linuxMatch10.0
Node
fedoraprojectfedoraMatch30
OR
fedoraprojectfedoraMatch31
OR
fedoraprojectfedoraMatch32
Node
opensuseleapMatch15.1
OR
opensuseleapMatch15.2
Node
canonicalubuntu_linuxMatch16.04esm
OR
canonicalubuntu_linuxMatch18.04lts
OR
canonicalubuntu_linuxMatch19.10
VendorProductVersionCPE
oraclejdk1.7.0cpe:2.3:a:oracle:jdk:1.7.0:update251:*:*:*:*:*:*
oraclejdk1.8.0cpe:2.3:a:oracle:jdk:1.8.0:update241:*:*:*:*:*:*
oraclejdk11.0.6cpe:2.3:a:oracle:jdk:11.0.6:*:*:*:*:*:*:*
oraclejdk14.0.0cpe:2.3:a:oracle:jdk:14.0.0:*:*:*:*:*:*:*
oraclejre1.7.0cpe:2.3:a:oracle:jre:1.7.0:update_251:*:*:*:*:*:*
oraclejre1.8.0cpe:2.3:a:oracle:jre:1.8.0:update_241:*:*:*:*:*:*
oraclejre11.0.6cpe:2.3:a:oracle:jre:11.0.6:*:*:*:*:*:*:*
oraclejre14.0.0cpe:2.3:a:oracle:jre:14.0.0:*:*:*:*:*:*:*
oracleopenjdk*cpe:2.3:a:oracle:openjdk:*:*:*:*:*:*:*:*
oracleopenjdk7cpe:2.3:a:oracle:openjdk:7:-:*:*:*:*:*:*
Rows per page:
1-10 of 1261

References

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

CVSS3

8.3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.002

Percentile

52.6%