Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:15667
HistoryMay 02, 2019 - 5:03 a.m.

Weak Encryption Parameters

2019-05-0205:03:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.009 Low

EPSS

Percentile

82.5%

The Diffie-Hellman (DH) key exchange algorithm implementation in the Security component in OpenJDK failed to validate public DH parameters properly. This could cause OpenJDK to accept and use weak parameters, allowing an attacker to recover the negotiated key.

References