Impact
This vulnerability affects the Java Secure Socket Extension (JSSE) component of Oracle Java SE. An unauthenticated attacker with network access can supply crafted data to exposed TLS APIs, enabling unauthorized creation, deletion, or modification of data that the Java runtime can access. The issue does not compromise confidentiality or availability, but it allows an attacker to alter critical information, thereby violating integrity. The attack requires TLS communication with the vulnerable service and does not rely on malicious Java applets or Web Start applications.
Affected Systems
Affected products include Oracle Java SE 8 (update 491 and performance build), 11.0.31, 17.0.19, 21.0.11, 25.0.3, and 26.0.1. These versions are listed as vulnerable in the CNA advisory.
Risk and Exploitability
The CVSS v3.1 base score is 5.9, indicating a moderate risk with an impact focused on integrity. The EPSS score is less than 1%, suggesting low probability of exploitation, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires network access over TLS and an ability to invoke specific JSSE APIs. The attacker does not need prior authentication or privileged access, but the exploitation path has high complexity due to the requirement of supplying precise data to the vulnerable interfaces.
OpenCVE Enrichment
Debian DLA
Debian DSA