Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:15664
HistoryMay 02, 2019 - 5:03 a.m.

Timing Attack

2019-05-0205:03:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.009

Percentile

82.5%

It was discovered that the RSA algorithm in the OpenJDK Security component did not sufficiently preform “blinding” while performing operations using private keys. An attacker able to measure timing differences of those operations could possibly leak information about the keys used.

References