First published: Tue Jul 14 2020(Updated: )
A flaw was found in the Grall compiler in the Hotspot component of OpenJDK. Incomplete checks of referenced data types could cause interface calls to accept incompatible types.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <11-openjdk-1:11.0.8.10-0.el7_8 | 11-openjdk-1:11.0.8.10-0.el7_8 |
redhat/java | <11-openjdk-1:11.0.8.10-0.el8_2 | 11-openjdk-1:11.0.8.10-0.el8_2 |
redhat/java | <11-openjdk-1:11.0.8.10-0.el8_0 | 11-openjdk-1:11.0.8.10-0.el8_0 |
redhat/java | <11-openjdk-1:11.0.8.10-0.el8_1 | 11-openjdk-1:11.0.8.10-0.el8_1 |
debian/openjdk-11 | 11.0.24+8-2~deb11u1 11.0.26+4-1~deb11u1 11.0.26+4-1 | |
Oracle OpenJDK 1.8.0 | =11.0.7 | |
Oracle OpenJDK 1.8.0 | =14.0.1 | |
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.50.2 | |
NetApp SANtricity Storage Manager | ||
NetApp SANtricity Unified Manager | ||
NetApp E-Series SANtricity Web Services | ||
Fedora | =31 | |
Fedora | =32 | |
SUSE Linux | =15.1 | |
SUSE Linux | =15.2 | |
Debian | =10.0 | |
Ubuntu | =18.04 | |
Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-14573 is a vulnerability in the Java SE product of Oracle Java SE that allows an unauthenticated attacker with network access to compromise Java SE.
Java SE versions 11.0.7 and 14.0.1 are affected by CVE-2020-14573.
CVE-2020-14573 has a severity rating of medium, with a CVSS score of 3.7.
An attacker can exploit CVE-2020-14573 by leveraging multiple protocols to compromise Java SE.
You can find more information about CVE-2020-14573 on the Oracle Security Alerts website and the Red Hat Errata website.