Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:18946
HistoryMay 16, 2019 - 2:18 a.m.

Information Disclosure

2019-05-1602:18:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.001 Low

EPSS

Percentile

44.6%

Oracle Java SE is vulnerable to information disclosure . This is because the LDAP component of OpenJDK fails to properly encode special characters in user names when adding them to an LDAP search query. Remote attackers could possibly use this flaw to manipulate LDAP queries performed by the LdapLoginModule class.

References