CVE-2020-2816: High severity Oracle JDK vulnerability
A flaw was found in the TLS/SSL implementation in the JSSE component of OpenJDK, where it did not properly handle application data packets received before the handshake completion. This flaw allowed unauthorized injection of data at the beginning of a TLS session.
Other sources
It was discovered that the TLS/SSL implementation in the JSEE component of OpenJDK did not properly handle application data packets received prior to the handshake completion. This could allow unauthorized injection of data at the beginning a TLS session.
— Red Hat
Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-2816?
CVE-2020-2816 is classified as a critical vulnerability due to its potential for unauthorized data injection during the TLS handshake.
How do I fix CVE-2020-2816?
To address CVE-2020-2816, update to the remedied versions of OpenJDK or the specified patched versions from your operating system's vendor.
Which versions are affected by CVE-2020-2816?
CVE-2020-2816 affects multiple versions of OpenJDK, including 11.0.6 and 14.0.0.
What components are impacted by CVE-2020-2816?
The flaw in CVE-2020-2816 impacts the TLS/SSL implementation within the JSSE component of OpenJDK.
Can CVE-2020-2816 lead to data breaches?
Yes, CVE-2020-2816 can enable attackers to inject unauthorized data, potentially leading to data breaches during the TLS session establishment.