Back

LOW

OpenJDK: Incorrect handling of empty string nodes in regular expression Parser (Scripting, 8223904)

Published Apr 15, 2020

Description

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (19)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner oracle
Published Apr 15, 2020
Updated Sep 30, 2024
Reserved Dec 10, 2019

CISA Vulnrichment

Updated Sep 30, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Low
Public date Apr 14, 2020
Bugzilla 1823200

ENISA EUVD

Assigner oracle
Published Apr 15, 2020
Updated Sep 30, 2024

GitHub

No data