Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:17869
HistoryMay 02, 2019 - 6:09 a.m.

Unauthenticated Access

2019-05-0206:09:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.005 Low

EPSS

Percentile

76.1%

oracle java SE is vulnerable to unauthenticated access vulnerability. This exists due to not validating the length of the object identifier read from the DER input in Libraries component of OpenJDK before allocating memory to store the OID. An attacker able to make a Java application decode a specially crafted DER input could cause the application to consume an excessive amount of memory.