Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21719
HistoryOct 17, 2019 - 12:22 a.m.

Remote Code Execution (RCE) Via Partial Denial Of Service (DoS)

2019-10-1700:22:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

0.001 Low

EPSS

Percentile

32.3%

OpenJDK is vulnerable to remote code execution (RCE). It is possible because it causes an unexpected exception thrown during Font object deserialization, leading to a partial denial of service (DoS) of Java SE. A client using a Java sandbox or using a Java web service with data supplies to APIs can be exploited to run a malicious code through this.

References