« Volver al listado

CVE-2010-3300

Estado: ModificadaMedia (5.9)—

It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-3300",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "OWASP ESAPI",
          "versions": [
            {
              "status": "affected",
              "version": "OWASP ESAPI for Java up to version 2.0 RC2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-06-22T12:15:08.840",
  "references": [
    {
      "url": "https://seclists.org/oss-sec/2010/q3/357",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://www.usenix.org/legacy/events/woot10/tech/full_papers/Rizzo.pdf",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://seclists.org/oss-sec/2010/q3/357",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.usenix.org/legacy/events/woot10/tech/full_papers/Rizzo.pdf",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-649"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks."
    },
    {
      "lang": "es",
      "value": "Se ha detectado que todos los OWASP ESAPI para Java hasta versión 2.0 RC2, son vulnerables a ataques de tipo padding oracle"
    }
  ],
  "lastModified": "2026-06-16T23:22:32.527",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:owasp:enterprise_security_api_for_java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A18BAA8C-904F-4669-B466-25A7325E00BB",
              "versionEndExcluding": "2.0"
            },
            {
              "criteria": "cpe:2.3:a:owasp:enterprise_security_api_for_java:2.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B905DADA-68DB-44A3-8C44-0935E69813FF"
            },
            {
              "criteria": "cpe:2.3:a:owasp:enterprise_security_api_for_java:2.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "888771B8-9537-4CB3-AD8A-FDD443C0ADCE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}