Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31347
HistoryJul 25, 2021 - 12:39 a.m.

Remote Code Execution (RCE)

2021-07-2500:39:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
30

0.001 Low

EPSS

Percentile

44.4%

Oracle Java SE is vulnerable to remote code execution. A flaw was found in the way the Library component of OpenJDK handled JAR files containing multiple MANIFEST.MF files. Such JAR files could cause signature verification process to return an incorrect result, possibly allowing tampering with signed JAR files. After the fix, all JAR files with multiple MANIFEST.MF files are treated as unsigned.