Advisory Published
Updated

REDHAT-BUG-2015648

First published: Tue Oct 19 2021(Updated: )

It was discovered that the default TLS cipher suite configuration in the JSSE component of OpenJDK preferred certain weak ciphers over stronger ciphers. This issue was addressed by: - Preferring ciphers with forward secrecy. - Lowering priority of ciphers using RSA encryption key exchange. - Lowering priority of ciphers using SHA-1 hashing algorithm. Upstream commit: <a href="https://github.com/openjdk/jdk11u/commit/af4b37301d33723806c38cf8ae5d85b7fa7ef39f">https://github.com/openjdk/jdk11u/commit/af4b37301d33723806c38cf8ae5d85b7fa7ef39f</a>

Affected SoftwareAffected VersionHow to fix
Sun JSSE

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of REDHAT-BUG-2015648?

    The severity of REDHAT-BUG-2015648 is significant due to the preference for weak TLS ciphers which can lead to potential security vulnerabilities.

  • How do I fix REDHAT-BUG-2015648?

    To fix REDHAT-BUG-2015648, update your OpenJDK JSSE to the latest version where the cipher suite configuration is corrected.

  • What are the risks associated with REDHAT-BUG-2015648?

    The risks associated with REDHAT-BUG-2015648 include data interception and denial of service due to the use of weak TLS ciphers.

  • Which versions of OpenJDK are affected by REDHAT-BUG-2015648?

    OpenJDK JSSE versions prior to the patch addressing REDHAT-BUG-2015648 are affected.

  • What changes were made to resolve REDHAT-BUG-2015648?

    The changes made to resolve REDHAT-BUG-2015648 include preferring ciphers with forward secrecy and lowering the priority of ciphers using RSA encryption.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203