Unauthorized Data Access in Oracle Java SE and JRockit
CVE-2018-2629
5.3MEDIUM
Summary
A vulnerability in Oracle Java SE and JRockit components allows an unauthenticated attacker with network access to compromise affected systems. This flaw requires human interaction from another person to successfully exploit it, which may lead to unauthorized creation, deletion, or modification of critical data. The exploitable nature of this vulnerability exists through both sandboxed Java Web Start applications and sandboxed Java applets, or through direct API data supply without sandboxing. It affects both client and server deployments of Java, making it particularly concerning for those relying on Java in their applications.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved