REDHAT-BUG-2041439: Medium severity OpenJDK JAXP vulnerability
It was discovered that the XMLEntityManager class implementation in the JAXP component of OpenJDK did not properly perform access checks. A Java application using SAX XML parser in certain configuration could be tricked into disclosing information when parsing a specially-crafted XML file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2041439?
The severity of REDHAT-BUG-2041439 is critical due to potential information disclosure vulnerabilities.
What software is affected by REDHAT-BUG-2041439?
REDHAT-BUG-2041439 affects the JAXP component of OpenJDK.
How do I fix REDHAT-BUG-2041439?
To fix REDHAT-BUG-2041439, update to the latest version of OpenJDK that includes the security patch.
What type of vulnerability is REDHAT-BUG-2041439?
REDHAT-BUG-2041439 is an information disclosure vulnerability related to improper access checks in the XMLEntityManager class.
What can be exploited in REDHAT-BUG-2041439?
Attackers can exploit REDHAT-BUG-2041439 by providing specially-crafted XML files to disclose sensitive information during parsing.