PT-2020-3575 · Oracle+5 · Oracle Java Se+6

Published

2020-07-14

·

Updated

2026-05-08

·

CVE-2020-14573

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 11.0.7 and 14.0.1
Description The issue is related to insufficient input validation in the Hotspot component of Oracle Java SE. It allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE, resulting in unauthorized update, insert, or delete access to some of Java SE's accessible data. This can be exploited through sandboxed Java Web Start applications, sandboxed Java applets, or by supplying data to APIs in the specified component without using sandboxed applications or applets. The vulnerability can be exploited using the HTTP protocol.
Recommendations For Oracle Java SE version 11.0.7, update to a version that includes the fix for this issue. For Oracle Java SE version 14.0.1, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Hotspot component until a patch is available. Avoid using the vulnerable APIs in the Hotspot component to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2020-03908
BIT-JAVA-2020-14573
BIT-JAVA-MIN-2020-14573
BIT-JRE-2020-14573
CESA-2020_2969
CESA-2020_2970
CVE-2020-14573
DSA-4734-1
OESA-2024-2485
OESA-2024-2486
OESA-2024-2487
OESA-2024-2488
OESA-2024-2489
OPENSUSE-SU-2020:1175-1
OPENSUSE-SU-2020:1191-1
OPENSUSE-SU-2020_1175-1
OPENSUSE-SU-2020_1191-1
OPENSUSE-SU-2024:10871-1
OPENSUSE-SU-2024:10872-1
OPENSUSE-SU-2024:10873-1
RHSA-2020:2969
RHSA-2020:2970
RHSA-2020:3098
RHSA-2020:3099
RHSA-2020_2969
RHSA-2020_2970
SUSE-SU-2020:2008-1
SUSE-SU-2020:2143-1
USN-4433-1

Affected Products

Centos
Java Platform
Linuxmint
Oracle Java Se
Red Hat
Suse
Ubuntu