CVE-2020-2767 is a vulnerability in the Java SE product's JSSE component, affecting versions 11.0.6 and 14. This flaw allows an unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful exploitation can lead to unauthorized modification or deletion of some Java SE accessible data, as well as unauthorized read access to a subset of that data. The vulnerability has a CVSS 3.0 Base Score of 4.8 (Medium), indicating low confidentiality and integrity impacts. It is difficult to exploit and does not require user interaction, applying to both client and server deployments. Exploitation can occur through sandboxed Java Web Start applications, applets, or by supplying data directly to APIs. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0.6CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:11.0.6:*:*:*:*:*:*:* | ||
14.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:14.0.0:*:*:*:*:*:*:* | ||
11.0.6CPE matchmatch criteria | cpe:2.3:a:oracle:jre:11.0.6:*:*:*:*:*:*:* | ||
14.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:14.0.0:*:*:*:*:*:*:* | ||
>= 11, <= 11.0.6CPE matchmatch criteria | cpe:2.3:a:oracle:openjdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.