Impact
Vulnerability exists in the Scripting component of Oracle Java SE. The flaw allows an unauthenticated attacker with network access to trigger a denial‑of‑service condition by forcing the JVM to hang or crash repeatedly. Because the weakness resides in a core runtime function, any Java application or service that invokes the scripting engine through exposed APIs can be impacted, including server‑side web services and sandboxed client apps that load untrusted code.
Affected Systems
Oracle Corporation’s Oracle Java SE has known vulnerable releases 8u491, 8u491‑perf, and 11.0.31. These versions are used in both server‑side deployments and legacy client applications that rely on the Java runtime for scripting tasks.
Risk and Exploitability
The CVSS base score of 7.5 highlights a high availability impact, while the EPSS score of less than 1% indicates that exploitation is currently unlikely but possible. The vulnerability can be triggered remotely over a variety of network protocols; the description notes that APIs in the affected component can be invoked, for example, via a web service that accepts data. The attack requires no authentication and can be performed by any host that can reach the Java runtime, making the risk significant for exposed services and for client environments that load external scripts.
OpenCVE Enrichment
Debian DLA