Impact
The vulnerability is in the Oracle Java SE 2D component and allows an unauthenticated attacker with network access to supply crafted data to vulnerable APIs. When that data is processed, Oracle Java SE can hang or repeatedly crash, resulting in a denial of service for Java applications that use the affected component. This issue does not compromise confidentiality or integrity; it solely impacts availability.
Affected Systems
Oracle Java SE 7u511 is affected. The vulnerability impacts the Java 2D component used by Java Web Start applications or sandboxed applets that rely on the Java sandbox to execute untrusted code.
Risk and Exploitability
Based on the CVSS score of 6.5 this vulnerability is rated as medium severity, with the primary impact on availability. The attack vector is an unauthenticated network attacker who can send malicious data to the vulnerable 2D APIs. Because no EPSS value is provided, the proportion of active exploitation cannot be precisely quantified. It is inferred that the risk is moderate in environments where the affected Java runtime is exposed to untrusted input. The vulnerability is not listed in the CISA KEV catalog, indicating no widespread or confirmed exploitation has been observed in the wild.
OpenCVE Enrichment