First published: Thu Jan 11 2024(Updated: )
An unspecified vulnerability in Java SE related to the Security component could allow a remote attacker to cause high confidentiality impact and high integrity impact.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Controller | <=11.0.0 - 11.0.1 | |
Oracle GraalVM Enterprise Edition | =20.3.12 | |
Oracle GraalVM Enterprise Edition | =21.3.8 | |
Oracle GraalVM Enterprise Edition | =22.3.4 | |
Oracle GraalVM for JDK | =17.0.9 | |
Oracle GraalVM for JDK | =21.0.1 | |
Oracle JDK 6 | =1.8.0-update391 | |
Oracle JDK 6 | =1.8.0-update391 | |
Oracle JDK 6 | =11.0.21 | |
Oracle JDK 6 | =17.0.9 | |
Oracle JDK 6 | =21.0.1 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update391 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update391 | |
Oracle Java Runtime Environment (JRE) | =11.0.21 | |
Oracle Java Runtime Environment (JRE) | =17.0.9 | |
Oracle Java Runtime Environment (JRE) | =21.0.1 | |
netapp cloud insights acquisition unit | ||
NetApp Cloud Insights Storage Workload Security Agent | ||
NetApp OnCommand Insight | ||
Debian GNU/Linux | =10.0 | |
debian/openjdk-11 | 11.0.24+8-2~deb11u1 11.0.26+4-1~deb11u1 11.0.26+4-1 | |
debian/openjdk-17 | 17.0.12+7-2~deb11u1 17.0.14+7-1~deb11u1 17.0.13+11-2~deb12u1 17.0.14+7-1~deb12u1 17.0.14+7-1 | |
debian/openjdk-21 | 21.0.6+7-1 | |
debian/openjdk-8 | 8u442-ga-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-20952 is classified as having a high confidentiality impact and high integrity impact.
To fix CVE-2024-20952, update your Java SE to the latest version that addresses this vulnerability.
Affected software includes specific versions of Oracle GraalVM, Oracle JDK, Oracle JRE, and IBM Cognos Controller, among others.
CVE-2024-20952 is caused by an RSA padding issue and timing vulnerabilities within the TLS implementation of the Security component in OpenJDK.
CVE-2024-20952 was reported through various security advisories, highlighting vulnerabilities discovered in the Java SE Security component.