3.7 Low
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
0.001 Low
EPSS
Percentile
23.0%
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition,
Oracle GraalVM for JDK product of Oracle Java SE (component: Hotspot).
Supported versions that are affected are Oracle Java SE: 8u371, 8u371-perf,
11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10,
21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and 20.0.1. Difficult to
exploit vulnerability allows unauthenticated attacker with network access
via multiple protocols to compromise Oracle Java SE, Oracle GraalVM
Enterprise Edition, Oracle GraalVM for JDK. Successful attacks of this
vulnerability can result in unauthorized read access to a subset of Oracle
Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK
accessible data. Note: This vulnerability can be exploited by using APIs in
the specified Component, e.g., through a web service which supplies data to
the APIs. This vulnerability also applies to Java deployments, typically in
clients running sandboxed Java Web Start applications or sandboxed Java
applets, that load and run untrusted code (e.g., code that comes from the
internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score
3.7 (Confidentiality impacts). CVSS Vector:
(CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 18.04 | noarch | openjdk-17 | < 17.0.8+7-1~18.04 | UNKNOWN |
ubuntu | 20.04 | noarch | openjdk-17 | < 17.0.8+7-1~20.04.2 | UNKNOWN |
ubuntu | 22.04 | noarch | openjdk-17 | < 17.0.8+7-1~22.04 | UNKNOWN |
ubuntu | 23.04 | noarch | openjdk-17 | < 17.0.8+7-1~23.04 | UNKNOWN |
ubuntu | 23.04 | noarch | openjdk-20 | < 20.0.2+9+ds1-0ubuntu1~23.04 | UNKNOWN |
ubuntu | 18.04 | noarch | openjdk-8 | < 8u382-ga-1~18.04.1 | UNKNOWN |
ubuntu | 20.04 | noarch | openjdk-8 | < 8u382-ga-1~20.04.1 | UNKNOWN |
ubuntu | 22.04 | noarch | openjdk-8 | < 8u382-ga-1~22.04.1 | UNKNOWN |
ubuntu | 23.04 | noarch | openjdk-8 | < 8u382-ga-1~23.04.1 | UNKNOWN |
ubuntu | 16.04 | noarch | openjdk-8 | < 8u382-ga-1~16.04.1 | UNKNOWN |