CVE-2020-14577 is a low-severity vulnerability in the Java SE and Java SE Embedded products, specifically affecting the JSSE component in versions 7u261, 8u251, 11.0.7, and 14.0.1. An unauthenticated attacker with network access via TLS can exploit this vulnerability, which is difficult to execute. Successful exploitation leads to unauthorized read access to a subset of Java SE/Embedded data, impacting confidentiality. This vulnerability applies to both client and server deployments and can be exploited through sandboxed applications or by supplying data to APIs. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7CPE matchmatch criteria | cpe:2.3:a:oracle:openjdk:7:-:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:a:oracle:openjdk:7:update1:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:a:oracle:openjdk:7:update10:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:a:oracle:openjdk:7:update101:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:a:oracle:openjdk:7:update11:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.