PT-2020-3530 · Oracle+6 · Java Se Embedded+8

Published

2020-07-14

·

Updated

2026-05-08

·

CVE-2020-14579

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Java SE versions 7u261 and 8u251 Java SE Embedded version 8u251
Description The issue is related to insufficient input validation in the Libraries component of Oracle Java SE and Java SE Embedded. It can be exploited by an unauthenticated attacker with network access via multiple protocols, potentially leading to a partial denial of service. This vulnerability can be exploited through sandboxed Java Web Start applications, sandboxed Java applets, or by supplying data to APIs in the specified component. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For Java SE versions 7u261 and 8u251, consider disabling the use of the Libraries component until a patch is available. For Java SE Embedded version 8u251, restrict access to the vulnerable component to minimize the risk of exploitation. As a temporary workaround, avoid using the vulnerable APIs in the specified component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2020-03862
BIT-JAVA-2020-14579
BIT-JAVA-MIN-2020-14579
BIT-JRE-2020-14579
CESA-2020_2968
CESA-2020_2972
CESA-2020_2985
CESA-2020_3386
CVE-2020-14579
DLA-2325-1
DSA-4734-1
MGASA-2020-0309
OPENSUSE-SU-2020:1893-1
OPENSUSE-SU-2020:2048-1
OPENSUSE-SU-2020:2083-1
OPENSUSE-SU-2020_1893-1
OPENSUSE-SU-2020_2048-1
OPENSUSE-SU-2020_2083-1
OPENSUSE-SU-2024:10875-1
OPENSUSE-SU-2024:10876-1
RHSA-2020:2968
RHSA-2020:2972
RHSA-2020:2985
RHSA-2020:3100
RHSA-2020:3101
RHSA-2020:3386
RHSA-2020:3387
RHSA-2020:3388
RHSA-2020:5585
RHSA-2020_2968
RHSA-2020_2972
RHSA-2020_2985
RHSA-2020_3386
RHSA-2020_3387
RHSA-2020_3388
RHSA-2020_5585
ROSA-SA-2023-2314
SUSE-SU-2020:14482-1
SUSE-SU-2020:14484-1
SUSE-SU-2020:2453-1
SUSE-SU-2020:2461-1
SUSE-SU-2020:2482-1
SUSE-SU-2020:2861-1
SUSE-SU-2020:3191-1
SUSE-SU-2020:3460-1
USN-4453-1

Affected Products

Centos
Ibm Aix
Java Platform
Java Se
Java Se Embedded
Linuxmint
Red Hat
Suse
Ubuntu