Impact
The vulnerability is an unauthenticated remote data modification flaw in Oracle Java SE's Scripting component. An attacker with network access can invoke vulnerable APIs, including those exposed by web services supplying data, to write beyond array boundaries, enabling unauthorized creation, deletion or modification of critical data or complete access to all Java SE-accessible data. The flaw is identified as CWE-787, an out-of-bounds write condition, and also involves improper handling of serialized data designated as CWE-502. Successful exploitation results in confidentiality and integrity compromise, but availability is not affected.
Affected Systems
Affected products include Oracle Java SE 8u491, 8u491-perf and Java SE 11.0.31. The weakness can impact Java deployments such as sandboxed Java Web Start applications or Java applets that load untrusted code from the internet, relying on the Java sandbox for security.
Risk and Exploitability
The CVSS Base Score is 7.4 and the EPSS score is below 1%. The vulnerability is not listed in CISA KEV. Attackers likely target the exposed APIs over various protocols, requiring network access and no user interaction. Due to the out-of-bounds write, the flaw is considered difficult to exploit but remains a significant risk for organizations relying on the specified Java versions.
OpenCVE Enrichment
Debian DLA