Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44526
HistoryNov 30, 2023 - 8:30 p.m.

Improper Authorization

2023-11-3020:30:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
openjdk
improper authorization
unauthenticated attacker
network access
compromise
unauthorized access
java sandbox
security
java web start
applets
untrusted code

3.1 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

6.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

23.2%

openjdk is vulnerable to Improper Authorization. An unauthenticated attacker with network access via multiple protocols is able to potentially compromise the system and gain unauthorized access to some data. This vulnerability requires human interaction and primarily affects Java deployments relying on the Java sandbox for security, typically clients running sandboxed Java Web Start applications or applets that load untrusted code.

3.1 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

6.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

23.2%