CVE-2020-2805 is a high-severity vulnerability in Oracle Java SE and Java SE Embedded (component: Libraries) affecting versions 7u251, 8u241, 11.0.6, and 14. This vulnerability allows an unauthenticated attacker to compromise affected Java deployments, particularly client-side sandboxed applications that load untrusted code. With a CVSS 3.0 Base Score of 8.3, successful exploitation requires human interaction and network access, leading to potential complete takeover (Confidentiality, Integrity, and Availability impacts). While difficult to exploit, attacks can significantly impact additional products beyond Java itself. Currently, there is no known public exploit code (Metasploit, Nuclei, ExploitDB) and it is not listed on the CISA KEV catalog. Community discussion and media coverage for this CVE are minimal, indicating low public awareness or active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update251:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update241:*:*:*:*:*:* | ||
11.0.6CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:11.0.6:*:*:*:*:*:*:* | ||
14.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:14.0.0:*:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update_251:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.