CVE-2020-2757: Low severity IBM Engineering Requirements Quality Assistant On-Premises vulnerability
A flaw was found in the Serialization component of OpenJDK. The invokeWriteObject() method of the ObjectStreamClass method failed to catch InstantiationError exception during object stream deserialization, which could cause an unexpected exception to be raised when processing an untrusted serialized input.
Other sources
An unspecified vulnerability in Java SE related to the Java SE Serialization component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
— IBM
CVE-2020-2756 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L). CVE-2020-2757 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
— F5
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-1:1.8.0.252.b09-2.el6_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-openjdk-1:1.7.0.261-2.6.22.1.el6_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.1-ibm-1:1.7.1.4.65-1jpp.1.el6_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el6_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-openjdk-1:1.7.0.261-2.6.22.2.el7_8 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-1:11.0.7.10-4.el7_8 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-1:1.8.0.252.b09-2.el7_8 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.1-ibm-1:1.7.1.4.65-1jpp.1.el7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-1:11.0.7.10-1.el8_1 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-1:1.8.0.252.b09-2.el8_1 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-ibm-1:1.8.0.6.10-1.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-1:1.8.0.252.b09-2.el8_0 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-1:11.0.7.10-1.el8_0 - Upgrade
Upgrade
debian/openjdk-11to a version that resolves this vulnerability.Fixed in 11.0.24+8-2~deb11u1Fixed in 11.0.30+7-1~deb11u1Fixed in 11.0.30+7-1 - Upgrade
Upgrade
debian/openjdk-8to a version that resolves this vulnerability.Fixed in 8u472-ga-1 - Upgrade
Upgrade
OpenJDK/Oracle Java SE (Serialization component)to a version that resolves this vulnerability.Fixed in 7u251 - Upgrade
Upgrade
OpenJDK/Oracle Java SE (Serialization component)to a version that resolves this vulnerability.Fixed in 8u241 - Upgrade
Upgrade
OpenJDK/Oracle Java SE (Serialization component)to a version that resolves this vulnerability.Fixed in 11.0.6 - Upgrade
Upgrade
OpenJDK/Oracle Java SE (Serialization component)to a version that resolves this vulnerability.Fixed in 14 - Upgrade
Upgrade
OpenJDK/Oracle Java SE Embedded (Serialization component)to a version that resolves this vulnerability.Fixed in 8u241 - Compensating control
Avoid exposing Java SE Serialization functionality to untrusted network input through APIs unless the endpoint is protected; this flaw can be exploited by supplying data to APIs in the Serialization component without using sandboxed Java Web Start applications or sandboxed Java applets (e.g., via a web service).
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-2757?
The severity of CVE-2020-2757 is low with a severity value of 3.7.
Which versions of Java SE are affected by CVE-2020-2757?
Java SE versions 7u251, 8u241, 11.0.6, and 14 are affected by CVE-2020-2757.
What is the vulnerability in Java SE related to CVE-2020-2757?
The vulnerability in Java SE related to CVE-2020-2757 is in the Serialization component.
How can an attacker exploit CVE-2020-2757?
The vulnerability CVE-2020-2757 is difficult to exploit and requires network access by an unauthenticated attacker.
How can I fix CVE-2020-2757?
To fix CVE-2020-2757, update your Java SE to version 7u251, 8u241, 11.0.6, or 14, depending on the affected version.