Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23757
HistoryApr 10, 2020 - 12:35 a.m.

Information Disclosure

2020-04-1000:35:29
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

EPSS

0.007

Percentile

80.7%

JRE proxy implementation is vulnerable to information disclosure. Two flaws were found in the JRE proxy implementation. An untrusted applet or application could use these flaws to discover the usernames of users running applets and applications, or obtain web browser cookies and use them for session hijacking attacks.

References