CVE-2020-2601: Medium severity Oracle JDK vulnerability
It was discovered that the Kerberos implementation in the Security component of OpenJDK used RSA-MD5 checksum in Ticket Granting Service (TGS) requests even though MD5 algorithm is no longer considered safe for such use case. A remote attacker could possibly use this flaw to manipulate TGS requests.
Other sources
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-1:1.8.0.242.b07-1.el6_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-openjdk-1:1.7.0.251-2.6.21.0.el6_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.1-ibm-1:1.7.1.4.70-1jpp.1.el6_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-1:11.0.6.10-1.el7_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-1:1.8.0.242.b08-0.el7_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-openjdk-1:1.7.0.251-2.6.21.0.el7_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.1-ibm-1:1.7.1.4.70-1jpp.1.el7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-ibm-1:1.8.0.6.20-1jpp.1.el7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-1:11.0.6.10-0.el8_1 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-1:1.8.0.242.b08-0.el8_1 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-ibm-1:1.8.0.6.15-1.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-1:1.8.0.242.b08-0.el8_0 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-1:11.0.6.10-0.el8_0 - Upgrade
Upgrade
debian/openjdk-11to a version that resolves this vulnerability.Fixed in 11.0.24+8-2~deb11u1Fixed in 11.0.31+11-1~deb11u1Fixed in 11.0.32~8ea-1 - Upgrade
Upgrade
debian/openjdk-8to a version that resolves this vulnerability.Fixed in 8u492-ga-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 11 July 2025
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-2601?
CVE-2020-2601 is classified as a medium severity vulnerability.
How do I fix CVE-2020-2601?
To fix CVE-2020-2601, update your OpenJDK to the recommended versions provided in the advisory.
What versions of OpenJDK are affected by CVE-2020-2601?
CVE-2020-2601 affects multiple versions of OpenJDK, including 1.7, 1.8, and 11.
Can CVE-2020-2601 be exploited remotely?
Yes, CVE-2020-2601 can potentially be exploited by a remote attacker.
What is the impact of CVE-2020-2601?
The impact of CVE-2020-2601 could allow an attacker to manipulate Ticket Granting Service requests.