CVE-2020-14782: Medium severity ibm cloud pak for automation vulnerability
A flaw was found in the way the Libraries component of OpenJDK handled blacklists of untrusted certificates. Alternate certificate encodings were not considered, causing certain certificate fingerprints to not be blacklisted, possibly leading to untrusted certificates being accepted.
Other sources
An unspecified vulnerability in Java SE related to the Libraries component could allow an unauthenticated attacker to cause no confidentiality impact, low integrity impact, and no availability impact.
— IBM
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-14782?
CVE-2020-14782 is an unspecified vulnerability in Java SE related to the Libraries component.
Which versions of Java SE are affected by CVE-2020-14782?
The affected versions are Java SE 7u271, 8u261, 11.0.8, and 15.
Are there any specific versions of Java SE Embedded affected by CVE-2020-14782?
Yes, Java SE Embedded 8u261 is affected by the vulnerability.
How can an attacker exploit CVE-2020-14782?
The vulnerability allows an unauthenticated attacker with network access to exploit it.
What is the severity of CVE-2020-14782?
The severity of CVE-2020-14782 is medium with a CVSS score of 3.7.