Description: | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java
SE (component: 2D). Supported versions that are affected are Java SE:
7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily
exploitable vulnerability allows unauthenticated attacker with network
access via multiple protocols to compromise Java SE, Java SE Embedded.
Successful attacks require human interaction from a person other than
the attacker and while the vulnerability is in Java SE, Java SE
Embedded, attacks may significantly impact additional products.
Successful attacks of this vulnerability can result in unauthorized
creation, deletion or modification access to critical data or all Java
SE, Java SE Embedded accessible data. Note: This vulnerability applies
to Java deployments, typically in clients running sandboxed Java Web
Start applications or sandboxed Java applets, that load and run
untrusted code (e.g., code that comes from the internet) and rely on
the Java sandbox for security. This vulnerability does not apply to
Java deployments, typically in servers, that load and run only trusted
code (e.g., code installed by an administrator). CVSS 3.1 Base Score
7.4 (Integrity impacts). CVSS Vector:
(CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).
|