Impact
The vulnerability resides in Oracle Java SE version 8u491 within the JavaFX component and permits an unauthenticated attacker with network access to read a restricted subset of data from the Java runtime. The attack requires interaction from a third party beyond the attacker and does not provide higher privileges or denial of service. The impact is strictly confidentiality‑only, as noted by the CVSS vector showing a low confidentiality impact and no impact on integrity or availability.
Affected Systems
Affected deployments are Oracle Java SE on client systems that rely on the sandbox to isolate untrusted Java Web Start applications or applets, typically those that execute code downloaded from the internet. Server side deployments that only run trusted, administrator‑installed code are not within the scope of the vulnerability.
Risk and Exploitability
The CVSS score of 3.1 indicates a low‑severity risk, and the EPSS score of less than 1% shows a very low probability of exploitation under current conditions. The vulnerability does not appear in the CISA KEV catalog. Exploitation requires the attacker to entice a user into interacting with a piece of untrusted Java code that can then read sandboxed data. Because of the high attack complexity and the need for user‑initiated action, the overall risk to exposed users is modest, but the presence of a confidentiality breach makes remediation advisable.
OpenCVE Enrichment