5.9 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
0.001 Low
EPSS
Percentile
41.2%
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition
product of Oracle Java SE (component: Hotspot). Supported versions that are
affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1;
Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Difficult to
exploit vulnerability allows unauthenticated attacker with network access
via multiple protocols to compromise Oracle Java SE, Oracle GraalVM
Enterprise Edition. Successful attacks of this vulnerability can result in
unauthorized creation, deletion or modification access to critical data or
all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data.
Note: This vulnerability applies to Java deployments, typically in clients
running sandboxed Java Web Start applications or sandboxed Java applets,
that load and run untrusted code (e.g., code that comes from the internet)
and rely on the Java sandbox for security. This vulnerability can also be
exploited by using APIs in the specified Component, e.g., through a web
service which supplies data to the APIs. CVSS 3.1 Base Score 5.9 (Integrity
impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 18.04 | noarch | icedtea-web | < any | UNKNOWN |
ubuntu | 20.04 | noarch | icedtea-web | < any | UNKNOWN |
ubuntu | 22.04 | noarch | icedtea-web | < any | UNKNOWN |
ubuntu | 23.10 | noarch | icedtea-web | < any | UNKNOWN |
ubuntu | 24.04 | noarch | icedtea-web | < any | UNKNOWN |
ubuntu | 16.04 | noarch | icedtea-web | < any | UNKNOWN |
ubuntu | 18.04 | noarch | openjdk-17 | < 17.0.4+8-1~18.04 | UNKNOWN |
ubuntu | 20.04 | noarch | openjdk-17 | < 17.0.4+8-1~20.04 | UNKNOWN |
ubuntu | 22.04 | noarch | openjdk-17 | < 17.0.4+8-1~22.04 | UNKNOWN |
ubuntu | 22.10 | noarch | openjdk-17 | < 17.0.4+8-1 | UNKNOWN |