Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:18953
HistoryMay 16, 2019 - 2:18 a.m.

Information Disclosure

2019-05-1602:18:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.002 Low

EPSS

Percentile

60.3%

Oracle Java SE is vulnerable to information disclosure attacks. This is because the JGSS component of OpenJDK ignores the value of the javax.security.auth.useSubjectCredsOnly property when using HTTP/SPNEGO authentication and always uses global credentials. A local attacker could possibly use this flaw to unauthorized access to critical data or complete access to all Java SE, Java SE Embedded accessible data.

References