Vulnerability in the Java SE product of Oracle Java SE (component: Advanced Management Console)
Published Apr 15, 2020
3.7
LOWCVSS 3.1
EPSS 2.51%
Description
Vulnerability in the Java SE product of Oracle Java SE (component: Advanced Management Console). The supported version that is affected is Java Advanced Management Console: 2.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected products
-
- Version Java Advanced Management Console: 2.16StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Oracle Corporation | Java | n/a |
|
- 2.16
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-22557 Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10332 x_refsource_CONFIRM
- https://security.netapp.com/advisory/ntap-20200416-0004/ x_refsource_CONFIRMThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-22557 | Advisory | |
| https://kc.mcafee.com/corporate/index?page=content&id=SB10332 | x_refsource_CONFIRM | |
| https://security.netapp.com/advisory/ntap-20200416-0004/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.oracle.com/security-alerts/cpuapr2020.html | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.