Impact
Vulnerability in the JavaFX component of Oracle Java SE allows an unauthenticated network attacker to compromise a Java execution environment that runs sandboxed untrusted code, such as Java Web Start applications or applets. The flaw requires human interaction from a user other than the attacker but can lead to unauthorized update, insert or delete operations on data accessible through the Java application, thereby impacting data integrity.
Affected Systems
Oracle Java SE 8u491, is affected. This product is used in client machines that run sandboxed Java Web Start applications or Java applets which load code from external sources such as the Internet. Server-side deployments that run only trusted code are not impacted by this vulnerability.
Risk and Exploitability
The vulnerability has a CVSS v3.1 base score of 3.1, indicating a low integrity impact. The EPSS score is less than 1 %, suggesting a very low likelihood of exploitation in the wild, and it is not listed in CISA’s KEV catalog. The attack likely occurs over network protocols that allow the delivery of untrusted Java code to a client. An attacker must first convince or coerce a user to run such a program, which reduces the practical risk to systems that regularly enforce strict download and execution policies.
OpenCVE Enrichment