5
CVE-2020-14621
- EPSS 4.35%
- Veröffentlicht 15.07.2020 18:15:27
- Zuletzt bearbeitet 27.05.2025 16:33:09
- Erkennungen
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 31
Fedoraproject ≫ Fedora Version 32
Mcafee ≫ Epolicy Orchestrator Version 5.9.0
Mcafee ≫ Epolicy Orchestrator Version 5.9.1
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update -
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_1
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_2
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_3
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_4
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_5
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_6
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_7
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_8
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Netapp ≫ 7-mode Transition Tool Version -
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Netapp ≫ Cloud Backup Version -
Netapp ≫ Cloud Secure Agent Version -
Netapp ≫ E-series Performance Analyzer Version -
Netapp ≫ E-series Santricity Os Controller Version >= 11.0.0 <= 11.70.2
Netapp ≫ E-series Santricity Storage Manager Version -
Netapp ≫ E-series Santricity Web Services Version - SwPlatform web_services_proxy
Netapp ≫ Oncommand Insight Version -
Netapp ≫ Oncommand Unified Manager Core Package Version -
Netapp ≫ Oncommand Workflow Automation Version -
Netapp ≫ Plug-in For Symantec Netbackup Version -
Netapp ≫ Santricity Unified Manager Version -
Netapp ≫ Snapmanager Version - SwPlatform oracle
Netapp ≫ Snapmanager Version - SwPlatform sap
Netapp ≫ Steelstore Cloud Integrated Storage Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.35% | 0.901 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| Oracle | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
https://www.oracle.com/security-alerts/cpujul2020.html
https://security.gentoo.org/glsa/202209-15
https://kc.mcafee.com/corporate/index?page=content&id=SB10332
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00019.html
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00027.html
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html
https://lists.debian.org/debian-lts-announce/2020/08/msg00021.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CFJPOYF3CWYEPCDOAOCNFJTQIKKWPHW/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFZ36XIW5ENQAW6BB7WHRFFTTJX7KGMR/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEPHBZPNSLX43B26DWKB7OS6AROTS2BO/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQUMIAON2YEFRONMIUVHAKYCIOLICDBA/
https://security.gentoo.org/glsa/202008-24
https://security.netapp.com/advisory/ntap-20200717-0005/
https://usn.ubuntu.com/4433-1/
https://usn.ubuntu.com/4453-1/
https://www.debian.org/security/2020/dsa-4734
https://lists.apache.org/thread.html/rf96c5afb26b596b4b97883aa90b6c0b0fc4c26aaeea7123c21912103%40%3Cj-users.xerces.apache.org%3E