First published: Thu Jan 11 2024(Updated: )
An unspecified vulnerability in Java SE related to the Security component could allow a remote attacker to cause high confidentiality impact and high integrity impact.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJDK 8 | >=11<11.0.24 | |
OpenJDK 8 | >=17<17.0.10 | |
OpenJDK 8 | >=21<21.0.2 | |
OpenJDK 8 | =8 | |
OpenJDK 8 | =8-milestone1 | |
OpenJDK 8 | =8-milestone2 | |
OpenJDK 8 | =8-milestone3 | |
OpenJDK 8 | =8-milestone4 | |
OpenJDK 8 | =8-milestone5 | |
OpenJDK 8 | =8-milestone6 | |
OpenJDK 8 | =8-milestone7 | |
OpenJDK 8 | =8-milestone8 | |
OpenJDK 8 | =8-milestone9 | |
OpenJDK 8 | =8-update101 | |
OpenJDK 8 | =8-update102 | |
OpenJDK 8 | =8-update11 | |
OpenJDK 8 | =8-update111 | |
OpenJDK 8 | =8-update112 | |
OpenJDK 8 | =8-update121 | |
OpenJDK 8 | =8-update131 | |
OpenJDK 8 | =8-update141 | |
OpenJDK 8 | =8-update151 | |
OpenJDK 8 | =8-update152 | |
OpenJDK 8 | =8-update161 | |
OpenJDK 8 | =8-update162 | |
OpenJDK 8 | =8-update171 | |
OpenJDK 8 | =8-update172 | |
OpenJDK 8 | =8-update181 | |
OpenJDK 8 | =8-update191 | |
OpenJDK 8 | =8-update192 | |
OpenJDK 8 | =8-update20 | |
OpenJDK 8 | =8-update201 | |
OpenJDK 8 | =8-update202 | |
OpenJDK 8 | =8-update211 | |
OpenJDK 8 | =8-update212 | |
OpenJDK 8 | =8-update221 | |
OpenJDK 8 | =8-update222 | |
OpenJDK 8 | =8-update231 | |
OpenJDK 8 | =8-update232 | |
OpenJDK 8 | =8-update241 | |
OpenJDK 8 | =8-update242 | |
OpenJDK 8 | =8-update25 | |
OpenJDK 8 | =8-update252 | |
OpenJDK 8 | =8-update262 | |
OpenJDK 8 | =8-update271 | |
OpenJDK 8 | =8-update281 | |
OpenJDK 8 | =8-update282 | |
OpenJDK 8 | =8-update291 | |
OpenJDK 8 | =8-update301 | |
OpenJDK 8 | =8-update302 | |
OpenJDK 8 | =8-update31 | |
OpenJDK 8 | =8-update312 | |
OpenJDK 8 | =8-update322 | |
OpenJDK 8 | =8-update332 | |
OpenJDK 8 | =8-update342 | |
OpenJDK 8 | =8-update352 | |
OpenJDK 8 | =8-update362 | |
OpenJDK 8 | =8-update372 | |
OpenJDK 8 | =8-update382 | |
OpenJDK 8 | =8-update392 | |
OpenJDK 8 | =8-update40 | |
OpenJDK 8 | =8-update402-b00 | |
OpenJDK 8 | =8-update402-b01 | |
OpenJDK 8 | =8-update402-b02 | |
OpenJDK 8 | =8-update402-b03 | |
OpenJDK 8 | =8-update402-b04 | |
OpenJDK 8 | =8-update402-b05 | |
OpenJDK 8 | =8-update45 | |
OpenJDK 8 | =8-update5 | |
OpenJDK 8 | =8-update51 | |
OpenJDK 8 | =8-update60 | |
OpenJDK 8 | =8-update65 | |
OpenJDK 8 | =8-update66 | |
OpenJDK 8 | =8-update71 | |
OpenJDK 8 | =8-update72 | |
OpenJDK 8 | =8-update73 | |
OpenJDK 8 | =8-update74 | |
OpenJDK 8 | =8-update77 | |
OpenJDK 8 | =8-update91 | |
OpenJDK 8 | =8-update92 | |
Oracle GraalVM Enterprise Edition | =20.3.12 | |
Oracle GraalVM Enterprise Edition | =21.3.8 | |
Oracle GraalVM Enterprise Edition | =22.3.4 | |
Oracle GraalVM for JDK | =17.0.9 | |
Oracle GraalVM for JDK | =21.0.1 | |
Oracle Java SE 7 | =1.8.0-update391 | |
Oracle Java SE 7 | =1.8.0-update391 | |
Oracle Java SE 7 | =11.0.21 | |
Oracle Java SE 7 | =17.0.9 | |
Oracle Java SE 7 | =21.0.1 | |
Oracle JRE | =1.8.0-update391 | |
Oracle JRE | =1.8.0-update391 | |
Oracle JRE | =11.0.21 | |
Oracle JRE | =17.0.9 | |
Oracle JRE | =21.0.1 | |
NetApp Cloud Insights Acquisition Unit | ||
NetApp Cloud Insights Storage Workload Security Agent | ||
NetApp OnCommand Insight | ||
Debian Linux | =10.0 | |
debian/openjdk-11 | 11.0.24+8-2~deb11u1 11.0.26+4-1~deb11u1 11.0.27~4ea-1 | |
debian/openjdk-17 | 17.0.12+7-2~deb11u1 17.0.14+7-1~deb11u1 17.0.14+7-1~deb12u1 17.0.15~5ea-1 | |
debian/openjdk-21 | 21.0.7~8ea-1 | |
debian/openjdk-8 | 8u442-ga-2 | |
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Software Stack | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Virtual Appliance | <=ISVG 10.0.2 | |
IBM Security Verify Governance Identity Manager Container | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-20952 is classified as having a high confidentiality impact and high integrity impact.
To fix CVE-2024-20952, update your Java SE to the latest version that addresses this vulnerability.
Affected software includes specific versions of Oracle GraalVM, Oracle JDK, Oracle JRE, and IBM Cognos Controller, among others.
CVE-2024-20952 is caused by an RSA padding issue and timing vulnerabilities within the TLS implementation of the Security component in OpenJDK.
CVE-2024-20952 was reported through various security advisories, highlighting vulnerabilities discovered in the Java SE Security component.