Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44524
HistoryNov 30, 2023 - 8:29 p.m.

Improper Authorization

2023-11-3020:29:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
openjdk
improper authorization
unauthenticated attacker
unauthorized access
java
security vulnerability

3.7 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

7.3 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.6%

openjdk is vulnerable to Improper Authorization. An unauthenticated attacker with network access is able to potentially compromise affected systems and gain unauthorized access to data. This vulnerability can be exploited through APIs and applies to Java deployments relying on the Java sandbox for security, making it particularly concerning for applications running untrusted code, such as Java Web Start applications and Java applets.

3.7 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

7.3 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.6%