# CVE-2010-3300

## Summary

- **CVE ID:** CVE-2010-3300
- **Severity:** UNKNOWN
- **CVSS Score:** 0.01
- **CWE:** CWE-649
- **Published:** Jun 22, 2021
- **Last Modified:** Mar 15, 2026

## Description

It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.

## Affected Products

- n/a — OWASP ESAPI (OWASP ESAPI for Java up to version 2.0 RC2)

## References

- [CNA](https://www.usenix.org/legacy/events/woot10/tech/full_papers/Rizzo.pdf)
- [CNA](https://seclists.org/oss-sec/2010/q3/357)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 42.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._