REDHAT-BUG-2015653: Medium severity OpenJDK JSSE vulnerability
A flaw was found in the SSL logger implementation in the JSSE component of OpenJDK. A malicious client could cause a Java application acting as TLS server to raise an unexpected exception during TLS handshake.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2015653?
The severity of REDHAT-BUG-2015653 is categorized as critical due to the potential for a malicious client to disrupt the TLS handshake process.
How do I fix REDHAT-BUG-2015653?
To resolve REDHAT-BUG-2015653, it is recommended to update your OpenJDK JSSE to the latest patched version provided by the vendor.
What software is affected by REDHAT-BUG-2015653?
REDHAT-BUG-2015653 affects the OpenJDK JSSE component used for SSL logging in Java applications.
What kind of attack can exploit REDHAT-BUG-2015653?
An attacker can exploit REDHAT-BUG-2015653 by sending malicious requests to a Java application acting as a TLS server during the handshake.
Is there a workaround for REDHAT-BUG-2015653?
There is no recommended workaround for REDHAT-BUG-2015653 other than upgrading to a secure version of OpenJDK JSSE.