Impact
The vulnerability resides in the installation component of Oracle Java SE, allowing a low‑privileged local attacker who has logged into the system to exploit installation APIs or APIs exposed by Java Web Start and applets. The lack of proper input validation or authorization lets the attacker execute code with the privileges of the Java runtime, leading to full control of the Java SE runtime, which compromises confidentiality, integrity and availability. Successful exploitation requires human interaction by a person other than the attacker.
Affected Systems
Affected are Oracle Java SE 8u491 and the performance‑optimized 8u491‑perf release. These are the Java SE 8 builds referenced in the advisory. Any installation of these exact builds on local systems without an update is vulnerable; newer Java SE versions are presumed unaffected.
Risk and Exploitability
The CVSS base score is 6.7, indicating a moderate severity, while the EPSS score is less than 1 %. The vulnerability is not listed in the CISA KEV catalog. Attackers must possess local low‑privilege access and rely on human interaction provided by a third party to supply data or trigger vulnerable APIs. Though the probability of exploitation in the wild is low, a successful attack would give the adversary full control over the Java SE runtime.
OpenCVE Enrichment