CVE-2024-20922

CVSS 3.1 Score 2.5 of 10 (low)

Details

Published Jan 16, 2024
Updated: Feb 2, 2024

Summary

CVE-2024-20922 is a vulnerability affecting Oracle Java SE and Oracle GraalVM Enterprise Edition, specifically JavaFX components. Affected versions include Oracle Java SE 8u391 and Oracle GraalVM Enterprise Edition 20.3.12 and 21.3.8. This issue is classified as difficult to exploit and enables unauthenticated attackers with access to the infrastructure to compromise Java SE and GraalVM Enterprise Edition. However, successful attacks require human interaction and may lead to unauthorized data access, impacting integrity. This vulnerability primarily concerns Java deployments that execute untrusted code, such as sandboxed Java Web Start applications or applets. It does not apply to Java deployments running only trusted code. The Base Score is 2.5 (Integrity impacts), with a CVSS Vector of (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Java Runtime Environment
  • Oracle Java Development Kit

Affected Vendors

  • BonqDAO