First published: Tue Apr 14 2020(Updated: )
A flaw was found in the way the TLS implementation in the JSSE component of OpenJDK handled unexpected Certificate messages during the TLS handshake. This could possibly allow an attacker to tamper with certificate verification performed during the handshake.
Affected Software | Affected Version | How to fix |
---|---|---|
Sun JSSE |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1823947 is classified as significant due to the potential for an attacker to tamper with certificate verification during the TLS handshake.
To fix REDHAT-BUG-1823947, you should update your OpenJDK JSSE to a version that includes the latest security patches addressing this vulnerability.
REDHAT-BUG-1823947 affects systems running the JSSE component of OpenJDK implementations.
If REDHAT-BUG-1823947 is exploited, attackers may be able to tamper with the TLS handshake, compromising the integrity of secure communications.
Currently, there are no known effective workarounds for REDHAT-BUG-1823947, so applying the security update is the recommended action.