Remote Code Execution Vulnerability in Oracle Java SE
CVE-2024-21210
3.7LOW
Summary
A vulnerability in Oracle Java SE allows unauthenticated attackers with network access to exploit the system. This vulnerability primarily affects various versions, enabling unauthorized updates, inserts, or deletions of accessible data. It can be exploited via APIs in the Hotspot component, commonly through web services. Additionally, the issue impacts Java deployments that run untrusted code within sandboxed environments such as Java Web Start applications or applets, posing significant risks to security.
Affected Version(s)
Oracle Java SE Oracle Java SE:8u421
Oracle Java SE Oracle Java SE:8u421-perf
Oracle Java SE Oracle Java SE:11.0.24
References
CVSS V3.1
Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved