Impact
The flaw resides in the JavaFX component of Oracle Java SE 8u491. An unauthenticated attacker who can reach the JavaFX APIs over a network protocol can trigger a partial denial of service. Successful exploitation does not grant code execution or privilege escalation; it simply disrupts the availability of the JavaFX component, causing services that rely on it to become unavailable or sluggish. The weakness is a classic example of CWE‑770, Excessive Resource Consumption.
Affected Systems
Oracle Java SE 8u491 is the affected version. The vulnerability applies to any deployment that exposes the JavaFX API, including clients running Java Web Start applications or sandboxed Java applets that load untrusted code via the internet.
Risk and Exploitability
The CVSS 3.1 base score of 5.3 indicates moderate severity focused on availability. The EPSS score of less than 1% suggests a low probability of exploitation in the wild at present, and the vulnerability is not cataloged in CISA’s KEV. The likely attack vector is an unauthenticated network attacker who can reach the JavaFX API endpoints with standard protocol calls.
OpenCVE Enrichment