CVE-2020-2778Use of a Broken or Risky Cryptographic Algorithm in Oracle Openjdk

Severity
3.7LOWNVD
EPSS
0.4%
top 37.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15
Latest updateMay 24

Description

Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Sta

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 2.2 | Impact: 1.4

Affected Packages7 packages

CVEListV5oracle_corporation/javaJava SE: 11.0.6, 14
NVDoracle/openjdk1111.0.6+4
NVDoracle/jdk11.0.6, 14.0.0+1
NVDoracle/jre11.0.6, 14.0.0+1
NVDnetapp/storagegrid9.0.09.0.4

Also affects: Debian Linux 10.0, Ubuntu Linux 16.04, 18.04, 19.10

🔴Vulnerability Details

3
GHSA
GHSA-g7gj-3cvp-r2pf: Vulnerability in the Java SE product of Oracle Java SE (component: JSSE)2022-05-24
OSV
CVE-2020-2778: Vulnerability in the Java SE product of Oracle Java SE (component: JSSE)2020-04-15
CVEList
CVE-2020-2778: Vulnerability in the Java SE product of Oracle Java SE (component: JSSE)2020-04-15

📋Vendor Advisories

4
Ubuntu
OpenJDK vulnerabilities2020-04-22
Oracle
Oracle Oracle Java SE Risk Matrix: JSSE — CVE-2020-27782020-04-15
Red Hat
OpenJDK: Incomplete enforcement of algorithm restrictions for TLS (JSSE, 8232424)2020-04-14
Debian
CVE-2020-2778: openjdk-11 - Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Suppor...2020

💬Community

1
Bugzilla
CVE-2020-2778 OpenJDK: Incomplete enforcement of algorithm restrictions for TLS (JSSE, 8232424)2020-04-14
CVE-2020-2778 — Oracle Openjdk vulnerability | cvebase