7.4

CVE-2020-14593

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OracleOpenjdk Version7 Update-
OracleOpenjdk Version7 Updateupdate1
OracleOpenjdk Version7 Updateupdate10
OracleOpenjdk Version7 Updateupdate101
OracleOpenjdk Version7 Updateupdate11
OracleOpenjdk Version7 Updateupdate111
OracleOpenjdk Version7 Updateupdate121
OracleOpenjdk Version7 Updateupdate13
OracleOpenjdk Version7 Updateupdate131
OracleOpenjdk Version7 Updateupdate141
OracleOpenjdk Version7 Updateupdate15
OracleOpenjdk Version7 Updateupdate151
OracleOpenjdk Version7 Updateupdate161
OracleOpenjdk Version7 Updateupdate17
OracleOpenjdk Version7 Updateupdate171
OracleOpenjdk Version7 Updateupdate181
OracleOpenjdk Version7 Updateupdate191
OracleOpenjdk Version7 Updateupdate2
OracleOpenjdk Version7 Updateupdate201
OracleOpenjdk Version7 Updateupdate21
OracleOpenjdk Version7 Updateupdate211
OracleOpenjdk Version7 Updateupdate221
OracleOpenjdk Version7 Updateupdate231
OracleOpenjdk Version7 Updateupdate241
OracleOpenjdk Version7 Updateupdate25
OracleOpenjdk Version7 Updateupdate251
OracleOpenjdk Version7 Updateupdate261
OracleOpenjdk Version8 Update-
OracleOpenjdk Version8 Updatemilestone1
OracleOpenjdk Version8 Updatemilestone2
OracleOpenjdk Version8 Updatemilestone3
OracleOpenjdk Version8 Updatemilestone4
OracleOpenjdk Version8 Updatemilestone5
OracleOpenjdk Version8 Updatemilestone6
OracleOpenjdk Version8 Updatemilestone7
OracleOpenjdk Version8 Updatemilestone8
OracleOpenjdk Version8 Updatemilestone9
OracleOpenjdk Version8 Updateupdate101
OracleOpenjdk Version8 Updateupdate102
OracleOpenjdk Version8 Updateupdate11
OracleOpenjdk Version8 Updateupdate111
OracleOpenjdk Version8 Updateupdate112
OracleOpenjdk Version8 Updateupdate121
OracleOpenjdk Version8 Updateupdate131
OracleOpenjdk Version8 Updateupdate141
OracleOpenjdk Version8 Updateupdate151
OracleOpenjdk Version8 Updateupdate152
OracleOpenjdk Version8 Updateupdate161
OracleOpenjdk Version8 Updateupdate162
OracleOpenjdk Version8 Updateupdate171
OracleOpenjdk Version8 Updateupdate172
OracleOpenjdk Version8 Updateupdate181
OracleOpenjdk Version8 Updateupdate191
OracleOpenjdk Version8 Updateupdate192
OracleOpenjdk Version8 Updateupdate20
OracleOpenjdk Version8 Updateupdate201
OracleOpenjdk Version8 Updateupdate202
OracleOpenjdk Version8 Updateupdate211
OracleOpenjdk Version8 Updateupdate212
OracleOpenjdk Version8 Updateupdate221
OracleOpenjdk Version8 Updateupdate222
OracleOpenjdk Version8 Updateupdate231
OracleOpenjdk Version8 Updateupdate232
OracleOpenjdk Version8 Updateupdate241
OracleOpenjdk Version8 Updateupdate242
OracleOpenjdk Version8 Updateupdate25
OracleOpenjdk Version8 Updateupdate252
OracleOpenjdk Version11
OracleOpenjdk Version11.0.1
OracleOpenjdk Version11.0.2
OracleOpenjdk Version11.0.3
OracleOpenjdk Version11.0.4
OracleOpenjdk Version11.0.5
OracleOpenjdk Version11.0.6
OracleOpenjdk Version11.0.7
OracleOpenjdk Version13
OracleOpenjdk Version13.0.1
OracleOpenjdk Version13.0.2
OracleOpenjdk Version13.0.3
OracleOpenjdk Version14
OracleJdk Version1.7.0 Updateupdate261
OracleJdk Version1.8.0 Updateupdate251
OracleJdk Version11.0.7
OracleJdk Version14.0.1
OracleJre Version1.7.0 Updateupdate261
OracleJre Version1.8.0 Updateupdate251
OracleJre Version11.0.7
OracleJre Version14.0.1
FedoraprojectFedora Version31
FedoraprojectFedora Version32
CanonicalUbuntu Linux Version16.04 SwEditionesm
CanonicalUbuntu Linux Version18.04 SwEditionlts
CanonicalUbuntu Linux Version20.04 SwEditionlts
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
OpensuseLeap Version15.1
OpensuseLeap Version15.2
NetappActive Iq Unified Manager SwPlatformwindows Version >= 7.3
NetappActive Iq Unified Manager SwPlatformvsphere Version >= 9.5
NetappCloud Backup Version-
NetappCloud Secure Agent Version-
NetappE-series Santricity Os Controller Version >= 11.0.0 <= 11.70.2
NetappE-series Santricity Web Services Version- SwPlatformweb_services_proxy
NetappOncommand Insight Version-
NetappSnapmanager Version- SwPlatformsap
NetappSnapmanager Version- Update- SwPlatformoracle
NetappStoragegrid Version >= 9.0.0 <= 9.0.4
NetappStoragegrid Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.606
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
nvd@nist.gov 7.4 2.8 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
secalert_us@oracle.com 7.4 2.8 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
https://usn.ubuntu.com/4433-1/
Third Party Advisory
https://usn.ubuntu.com/4453-1/
Third Party Advisory