CVE-2020-14581: Medium severity Oracle JDK vulnerability
An unspecified vulnerability in Oracle Java SE and Java SE Embedded related to the 2D component could allow an unauthenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors.
Other sources
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this Oracle Java SE and Java SE Embedded vulnerability?
The vulnerability ID is CVE-2020-14581.
What is the severity of CVE-2020-14581?
The severity of CVE-2020-14581 is low, with a severity value of 3.7.
How can an unauthenticated attacker exploit CVE-2020-14581?
The specific attack vectors for CVE-2020-14581 are unknown.
What impact does CVE-2020-14581 have on confidentiality?
CVE-2020-14581 has a low confidentiality impact.
Is there a fix available for CVE-2020-14581?
Please refer to the official Oracle documentation or contact their support for information on available fixes.