Impact
A vulnerability in the JavaFX component of Oracle Java SE 8u491, classified as a CWE‑284 Access Control Failure, renders the sandbox ineffective. An unauthenticated attacker with network access can attempt exploitation, but a separate human interaction from a third party is required for a successful compromise. When achieved, the attacker can manipulate, insert, or delete data that the Java application has access to, impacting the integrity of that data. No confidentiality or availability impact is reported.
Affected Systems
The flaw affects Oracle Java SE 8u491, specifically those client deployments that rely on the Java sandbox for security, such as Java Web Start applications and sandboxed applets that load code from the internet. Server deployments that only run trusted code are not impacted.
Risk and Exploitability
The CVSS v3.1 base score of 3.1 reflects a low to moderate risk, with a high complexity but only requiring network access. The EPSS score indicates a probability of approximately 0.2 % and the vulnerability is not listed in CISA’s KEV catalog. The requirement for a separate human interaction and the need to exploit the JavaFX sandbox make widespread exploitation unlikely, but the integrity consequences for affected client systems remain a concern.
OpenCVE Enrichment