TROYANOSYVIRUS
Retour aux CVEs

CVE-2020-2816

HIGH
7.5

Description

Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

Details CVE

Score CVSS v3.17.5
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie4/15/2020
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

canonical:ubuntu_linuxdebian:debian_linuxnetapp:7-mode_transition_toolnetapp:active_iq_unified_managernetapp:cloud_backupnetapp:e-series_performance_analyzernetapp:e-series_santricity_os_controllernetapp:e-series_santricity_web_servicesnetapp:oncommand_insightnetapp:oncommand_workflow_automationnetapp:plug-in_for_symantec_netbackupnetapp:santricity_unified_managernetapp:snapmanagernetapp:steelstore_cloud_integrated_storagenetapp:storagegridopensuse:leaporacle:jdkoracle:jreoracle:openjdk

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.