CVE-2020-14797: Input Validation
An unspecified vulnerability in Java SE related to the Libraries component could allow an unauthenticated attacker to cause no confidentiality impact, low integrity impact, and no availability impact.
Other sources
It was discovered that the UnixUriUtils class in the Libraries component of OpenJDK did not properly check for invalid characters when performing URI to Path conversion. This could lead to creating Path objects with invalid paths.
— Red Hat
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-14797?
CVE-2020-14797 is an unspecified vulnerability in Java SE related to the Libraries component.
Which versions of Java SE are affected by CVE-2020-14797?
Java SE versions 7u271, 8u261, 11.0.8, and 15 are affected by CVE-2020-14797.
How can an attacker exploit CVE-2020-14797?
CVE-2020-14797 is a difficult to exploit vulnerability that allows an unauthenticated attacker with network access.
What is the severity of CVE-2020-14797?
CVE-2020-14797 has a severity of medium (3.7).
Where can I find more information about CVE-2020-14797?
You can find more information about CVE-2020-14797 at the following references: [Link 1](https://www.oracle.com/security-alerts/cpuoct2020.html#AppendixJAVA), [Link 2](https://access.redhat.com/errata/RHSA-2020:4306), [Link 3](https://access.redhat.com/errata/RHSA-2020:4305).