REDHAT-BUG-1299073: Medium severity OpenJDK JMX vulnerability
It was discovered that the RMIConnector and RMIConnectionImpl classes in the JMX component of OpenJDK could log sensitive information such as user passwords in its debug log, possibly leading the exposure of the information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1299073?
The severity of REDHAT-BUG-1299073 is considered high due to the potential exposure of sensitive information such as user passwords.
How do I fix REDHAT-BUG-1299073?
To fix REDHAT-BUG-1299073, update OpenJDK to the latest version that addresses this vulnerability and ensure sensitive information is not logged.
What vulnerable components are involved in REDHAT-BUG-1299073?
The vulnerable components involved in REDHAT-BUG-1299073 are the RMIConnector and RMIConnectionImpl classes in the JMX component of OpenJDK.
What could happen if REDHAT-BUG-1299073 is exploited?
If REDHAT-BUG-1299073 is exploited, attackers could gain access to sensitive information such as user passwords from the debug logs.
Who is affected by REDHAT-BUG-1299073?
The users of OpenJDK JMX are affected by REDHAT-BUG-1299073, specifically those utilizing the logging features of the RMI classes.