← Back

CVE-2020-2604

nvd nist
Published: Jan 15, 2020Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS v3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected (68)

Show all products
6 products
Commerce Experience Manager
Commerce Guided Search
Graalvm
Jdk
Jre
Openjdk
7 products
Enterprise Linux
Enterprise Linux Desktop
Enterprise Linux Eus
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Server Tus
Enterprise Linux Workstation
1 product
Debian Linux
1 product
Ubuntu Linux
1 product
Leap
10 products
Active Iq Unified Manager
E Series Performance Analyzer
E Series Santricity Os Controller
Oncommand Insight
Oncommand Workflow Automation
Santricity Unified Manager
1 product
Epolicy Orchestrator
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.3.2
Version 11.3.2
Version 19.3.0.2
Oracle
Version 1.7.0 update241
Version 1.8.0 update231
Version 11.0.5
Version 13.0.1
Version 1.8.0 update231
Configuration B
11 vulnerable
Configuration C
23 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
From 11 to 11.0.5
From 13 to 13.0.1
Version 7
Version 7 update241
Version 7 update80
Version 7 update85
Version 8
Version 8 update102
Version 8 update112
Version 8 update152
Version 8 update162
Version 8 update172
Version 8 update192
Version 8 update202
Version 8 update20
Version 8 update212
Version 8 update222
Version 8 update232
Version 8 update40
Version 8 update60
Version 8 update66
Version 8 update72
Version 8 update92
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 8.0
Version 9.0
Configuration E
3 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 16.04
Version 18.04
Version 19.10
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.1
Configuration G
11 vulnerable
Configuration H
9 vulnerable
Vulnerable SoftwareAffected Versions
Mcafee
Version 5.10.0
Version 5.10.0 update_1
Version 5.10.0 update_2
Version 5.10.0 update_3
Version 5.10.0 update_4
Version 5.10.0 update_5
Version 5.10.0 update_6
Version 5.9.0
Version 5.9.1

References (48)

Source: secalert_us@oracle.com
Mailing ListThird Party Advisory
Source: secalert_us@oracle.com
Mailing ListThird Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Mailing ListThird Party Advisory
Source: secalert_us@oracle.com
Issue TrackingMailing ListThird Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
PatchVendor Advisory
Source: secalert_us@oracle.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.