REDHAT-BUG-1639834: High severity ORACLE OpenJDK vulnerability
It was discovered that the JNDI comment of OpenJDK did not properly enforce the restriction controlled by the com.sun.jndi.ldap.object.trustURLCodebase system property. In certain cases, a Java LDAP client could unexpectedly load and execute code form an LDAP server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1639834?
The severity of REDHAT-BUG-1639834 is considered high due to the potential for remote code execution.
How do I fix REDHAT-BUG-1639834?
To fix REDHAT-BUG-1639834, users should update to the latest version of OpenJDK where the vulnerability has been patched.
What does the vulnerability REDHAT-BUG-1639834 affect?
REDHAT-BUG-1639834 affects OpenJDK, particularly versions that do not properly enforce URL codebase restrictions.
How does REDHAT-BUG-1639834 operate?
REDHAT-BUG-1639834 allows a Java LDAP client to potentially load and execute malicious code from an LDAP server due to insufficient enforcement of security controls.
Who is affected by REDHAT-BUG-1639834?
Developers and organizations using vulnerable versions of OpenJDK are at risk from the exploitation of REDHAT-BUG-1639834.