CVE-2020-14781: Medium severity ibm cloud pak for automation vulnerability
An unspecified vulnerability in Java SE related to the JNDI component could allow an unauthenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors.
Other sources
It was discovered that the LDAP client implementation in the JNDI component of OpenJDK did not properly track whether a connection to a server uses TLS encryption, and consequently did not properly restrict the set of authentication mechanisms that were allowed to be used over an unencrypted connection. This could possibly lead to sending of plain text authentication credentials over an unencrypted connection.
— Red Hat
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this Java SE vulnerability?
The vulnerability ID for this Java SE vulnerability is CVE-2020-14781.
What is the affected software for this vulnerability?
The affected software for this vulnerability is Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261.
How severe is CVE-2020-14781?
CVE-2020-14781 has a severity rating of medium (3.7).
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-319.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [Oracle Security Alerts](https://www.oracle.com/security-alerts/cpuoct2020.html#AppendixJAVA), [Java SE 15.0.1 Release Notes](https://www.oracle.com/java/technologies/javase/15-0-1-relnotes.html), [Java SE 11.0.9 Release Notes](https://www.oracle.com/java/technologies/javase/11-0-9-relnotes.html).