Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23753
HistoryApr 10, 2020 - 12:35 a.m.

Authentication Bypass

2020-04-1000:35:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
28

0.973 High

EPSS

Percentile

99.9%

java is vulnerable to authentication bypass. A flaw was found in the way the XML Digital Signature implementation in the JRE handled HMAC-based XML signatures. An attacker could use this flaw to create a crafted signature that could allow them to bypass authentication, or trick a user, applet, or application into accepting untrusted content.

References