Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:17952
HistoryMay 02, 2019 - 6:10 a.m.

Unauthorized Modification

2019-05-0206:10:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

EPSS

0.002

Percentile

57.4%

Java SE and Java SE Embedded are vulnerable to unauthenticated modification attacks. An unauthenticated attacker can exploit a flaw in the Security component of OpenJDK which does not allow users to restrict the set of algorithms allowed for Jar integrity verification allowing an attacker to modify content of the Jar file that use weak signing key or hash algorithm.