MEDIUM · 5.9

CVE-2010-3300

It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.

Vulnerability Description

It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
OwaspEnterprise Security Api For Java< 2.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-3300?

CVE-2010-3300 is a vulnerability with a CVSS score of 5.9 (MEDIUM). It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.

How severe is CVE-2010-3300?

CVE-2010-3300 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-3300?

Check the references section above for vendor advisories and patch information. Affected products include: Owasp Enterprise Security Api For Java.