Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20909
HistoryJul 29, 2019 - 12:08 a.m.

Information Disclosure

2019-07-2900:08:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

0.003 Low

EPSS

Percentile

65.3%

openjdk is vulnerable to information disclosure. It was discovered that the AccessController class implementation in the Security component of OpenJDK failed, in certain cases, to consider the current context and correctly restrict privileges based on it. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions and obtain authorized read access.