Remote Code Execution Vulnerability in Oracle Java SE
CVE-2024-21210

3.7LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 October 2024

Summary

A vulnerability in Oracle Java SE allows unauthenticated attackers with network access to exploit the system. This vulnerability primarily affects various versions, enabling unauthorized updates, inserts, or deletions of accessible data. It can be exploited via APIs in the Hotspot component, commonly through web services. Additionally, the issue impacts Java deployments that run untrusted code within sandboxed environments such as Java Web Start applications or applets, posing significant risks to security.

Affected Version(s)

Oracle Java SE Oracle Java SE:8u421

Oracle Java SE Oracle Java SE:8u421-perf

Oracle Java SE Oracle Java SE:11.0.24

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.