Impact
The Oracle Java SE 8u491 release contains a weakness in the JavaFX component that can, if successfully exploited, allow an unauthenticated attacker to read a limited set of data stored within the Java runtime. This flaw is difficult to exploit and requires a separate user to interact with a sandboxed client‑side application; the vulnerability does not affect server deployments that run only trusted code. Based on the description, the impact is confined to confidentiality, allowing the attacker to see data that the Java sandbox was intended to protect, such as credentials or configuration files, without affecting integrity or availability.
Affected Systems
The vulnerability applies to clients running Oracle Java SE 8 update 491 that execute sandboxed Java Web Start applications or applets. Deployments that load only trusted code on servers, as is typically configured, are not affected. Administrators should confirm that their installations match the affected version and that no client‑side sandboxed applications rely on the vulnerable JavaFX classes. The scope is limited to those environments that use JavaFX from untrusted sources.
Risk and Exploitability
With a CVSS score of 3.1 and an EPSS value of less than 1 %, the likelihood of real‑world exploitation is very low, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector involves network access via the Java Runtime's multiple protocols, combined with a required secondary user interaction. Based on the description, it is inferred that successful exploitation would require an attacker to supply a malicious payload to a sandboxed client, trigger the flaw, and have a distinct user execute the application, thereby constraining the attack surface.
OpenCVE Enrichment