PT-2020-2599 · Oracle+4 · Java Se+5

Published

2020-04-14

·

Updated

2026-05-08

·

CVE-2020-2816

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Java SE versions 11.0.6 and 14
Description The issue is related to insufficient input validation in the JSSE component of Oracle Java SE. It allows an unauthenticated attacker with network access via HTTPS to compromise Java SE, resulting in unauthorized creation, deletion, or modification access to critical data or all Java SE accessible data. This can be exploited by supplying data to APIs in the specified component without using untrusted Java Web Start applications or untrusted Java applets, such as through a web service.
Recommendations For Java SE version 11.0.6, update to a version that includes the fix for this issue. For Java SE version 14, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the JSSE component until a patch is available. Avoid using the JSSE component for untrusted connections or inputs until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2020-02633
BIT-JAVA-2020-2816
BIT-JAVA-MIN-2020-2816
BIT-JRE-2020-2816
CESA-2020_1509
CESA-2020_1514
CVE-2020-2816
DSA-4662-1
OPENSUSE-SU-2020:0757-1
OPENSUSE-SU-2020_0757-1
OPENSUSE-SU-2024:10871-1
OPENSUSE-SU-2024:10872-1
RHSA-2020:1509
RHSA-2020:1514
RHSA-2020:1517
RHSA-2020_1509
RHSA-2020_1514
SUSE-SU-2020:1511-1
SUSE-SU-2020:1511-2
SUSE-SU-2020:1572-1
SUSE-SU-2020_1511-1
SUSE-SU-2020_1511-2
SUSE-SU-2020_1572-1
USN-4337-1

Affected Products

Centos
Java Platform
Java Se
Red Hat
Suse
Ubuntu