Missing Encryption of Sensitive Data in Java SE Embedded - CVE-2020-14781
Published: October 21, 2020 / Updated: March 20, 2022
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The vulnerability exists due to improper input validation within the JNDI component in Java SE Embedded when processing encrypted LDAP requests. A remote non-authenticated attacker can downgrade the encrypted LDAP connection and gain access to sensitive information.
Affected software
Engineering Lifecycle Management
Oracle Java SE
Amazon Linux AMI
Gentoo Linux
IBM Security Identity Manager Virtual Appliance
Debian Linux
Red Hat Enterprise Linux Desktop
CentOS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
IBM AIX
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Opensuse
Ubuntu
Fedora
BIG-IP
IBM Operations Analytics Predictive Insights
IBM Cloud Transformation Advisor
IBM Sterling Control Center
WebSphere eXtreme Scale
IBM Cloud Application Business Insights
IBM Tivoli Monitoring
IBM CICS TX on Cloud
java-1.7.1-ibm (Red Hat package)
openjdk7 (Alpine package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
openjdk8 (Alpine package)
openjdk11 (Alpine package)
java-1.8.0-ibm (Red Hat package)
java-1.8.0-openjdk
openjdk-8-jdk (Ubuntu package)
openjdk-8-jre-zero (Ubuntu package)
openjdk-8-jre (Ubuntu package)
openjdk-8-jre-headless (Ubuntu package)
openjdk-11-jre-headless (Ubuntu package)
openjdk-11-jre-zero (Ubuntu package)
openjdk-11-jdk (Ubuntu package)
openjdk-11-jre (Ubuntu package)
java-11-openjdk (Red Hat package)
java-11-openjdk
openjdk-11 (Debian package)
IBM VIOS
IBM Tivoli Netcool Configuration Manager
IBM Security Directory Suite
IBM OS Image for Red Hat Linux Systems
Data Computing Appliance (DCA)
Solutions Enabler
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
BIG-IQ Centralized Management
IBM Cloud Pak System
RSA Authentication Manager
Solutions Enabler Virtual Appliance
How to mitigate CVE-2020-14781
Engineering Lifecycle Management - addressed in versions 6.0.6, 7.0.2
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.14
IBM Security Directory Suite - update to 8.0.1.16
openjdk8 (Alpine package) - update to 8.272.10-r0
openjdk11 (Alpine package) - update to 11.0.9_p11-r0
IBM Cloud Application Business Insights - addressed in versions 1.1.5.4, 1.1.6.3
java-1.8.0-ibm (Red Hat package) - addressed in versions 1.8.0.6.25-1jpp.1.el7, 1.8.0.6.25-2.el8_3
java-1.8.0-openjdk - addressed in versions 1.8.0.272.b10-0.fc31, 1.8.0.272.b10-0.fc32, 1.8.0.272.b10-0.fc33
IBM Cloud Pak System - update to 2.3.3.7
IBM OS Image for Red Hat Linux Systems - update to 3.1.3.0
Data Computing Appliance (DCA) - update to 4.3.0.0
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 7
openjdk-8-jdk (Ubuntu package) - addressed in versions 8u272-b10-0ubuntu1~16.04, 8u272-b10-0ubuntu1~18.04, 8u272-b10-0ubuntu1~20.04, 8u272-b10-0ubuntu1~20.10, 8u275-b01-0ubuntu1~16.04, 8u275-b01-0ubuntu1~18.04, 8u275-b01-0ubuntu1~20.04, 8u275-b01-0ubuntu1~20.10
openjdk-8-jre-zero (Ubuntu package) - addressed in versions 8u272-b10-0ubuntu1~16.04, 8u272-b10-0ubuntu1~18.04, 8u272-b10-0ubuntu1~20.04, 8u272-b10-0ubuntu1~20.10, 8u275-b01-0ubuntu1~16.04, 8u275-b01-0ubuntu1~18.04, 8u275-b01-0ubuntu1~20.04, 8u275-b01-0ubuntu1~20.10
openjdk-8-jre (Ubuntu package) - addressed in versions 8u272-b10-0ubuntu1~16.04, 8u272-b10-0ubuntu1~18.04, 8u272-b10-0ubuntu1~20.04, 8u272-b10-0ubuntu1~20.10, 8u275-b01-0ubuntu1~16.04, 8u275-b01-0ubuntu1~18.04, 8u275-b01-0ubuntu1~20.04, 8u275-b01-0ubuntu1~20.10
openjdk-8-jre-headless (Ubuntu package) - addressed in versions 8u272-b10-0ubuntu1~16.04, 8u272-b10-0ubuntu1~18.04, 8u272-b10-0ubuntu1~20.04, 8u272-b10-0ubuntu1~20.10, 8u275-b01-0ubuntu1~16.04, 8u275-b01-0ubuntu1~18.04, 8u275-b01-0ubuntu1~20.04, 8u275-b01-0ubuntu1~20.10
RSA Authentication Manager - update to 8.5 Patch 2
Solutions Enabler - addressed in versions 9.1.0.12, 9.2.0.1
Solutions Enabler Virtual Appliance - addressed in versions 9.1.0.12, 9.2.0.1
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.1.0.24, 9.2.0.6
Unisphere for PowerMax - addressed in versions 9.1.0.24, 9.2.0.6
IBM CICS TX on Cloud - update to 10.1.0.0 SpecialFIX Java 042021
openjdk-11-jre-headless (Ubuntu package) - addressed in versions 11.0.9.1+1-0ubuntu1~18.04, 11.0.9.1+1-0ubuntu1~20.04, 11.0.9.1+1-0ubuntu1~20.10, 11.0.9+11-0ubuntu1~18.04.1, 11.0.9+11-0ubuntu1~20.04
openjdk-11-jre-zero (Ubuntu package) - addressed in versions 11.0.9.1+1-0ubuntu1~18.04, 11.0.9.1+1-0ubuntu1~20.04, 11.0.9.1+1-0ubuntu1~20.10, 11.0.9+11-0ubuntu1~18.04.1, 11.0.9+11-0ubuntu1~20.04
openjdk-11-jdk (Ubuntu package) - addressed in versions 11.0.9.1+1-0ubuntu1~18.04, 11.0.9.1+1-0ubuntu1~20.04, 11.0.9.1+1-0ubuntu1~20.10, 11.0.9+11-0ubuntu1~18.04.1, 11.0.9+11-0ubuntu1~20.04
openjdk-11-jre (Ubuntu package) - addressed in versions 11.0.9.1+1-0ubuntu1~18.04, 11.0.9.1+1-0ubuntu1~20.04, 11.0.9.1+1-0ubuntu1~20.10, 11.0.9+11-0ubuntu1~18.04.1, 11.0.9+11-0ubuntu1~20.04
java-11-openjdk (Red Hat package) - addressed in versions 11.0.9.11-0.el7_9, 11.0.9.11-0.el8_0, 11.0.9.11-0.el8_1, 11.0.9.11-0.el8_2
java-11-openjdk - addressed in versions 11.0.9.11-0.fc31, 11.0.9.11-0.fc32, 11.0.9.11-0.fc33
openjdk-11 (Debian package) - update to 11.0.9+11-1~deb10u1
External References
Related Security Bulletins
- Multiple vulnerabilities in Java SE Embedded
- Multiple vulnerabilities in Java SE
- Red Hat Enterprise Linux 7 update for java-1.8.0-openjdk
- Red Hat Enterprise Linux 8.1 update for java-1.8.0-openjdk
- Red Hat Enterprise Linux 6 update for java-1.8.0-openjdk
- Red Hat Enterprise Linux 8 update for java-1.8.0-openjdk
- Red Hat Enterprise Linux 8 update for java-1.8.0-openjdk
- Improper input validation in openjdk11 (Alpine package)
- CentOS 6 update for java-1.8.0-openjdk
- OpenSUSE Linux update for java-1_8_0-openj9
- Improper input validation in openjdk8 (Alpine package)
- Amazon Linux AMI update for java-1.8.0-openjdk
- Red Hat Enterprise Linux 7 Supplementary update for java-1.7.1-ibm
- Improper input validation in openjdk7 (Alpine package)
- Amazon Linux AMI update for java-1.8.0-openjdk
- Gentoo update for OpenJDK
- Red Hat Enterprise Linux 7 Supplementary update for java-1.8.0-ibm
- Red Hat Enterprise Linux 8 update for java-1.8.0-ibm
- IBM AIX update for Java SDK
- Multiple vulnerabilities in IBM Engineering Lifecycle Management
- Information disclosure in IBM Sterling Control Center
- Multiple vulnerabilities in IBM WebSphere eXtreme Scale
- Debian update for openjdk-11
- Multiple vulnerabilities in IBM Security Directory Suite
- Information disclosure in IBM Tivoli Netcool Configuration Manager
- Information disclosure in IBM Operations Analytics Predictive Insights
- Multiple vulnerabilities in IBM OS Image for Red Hat Linux Systems
- Multiple vulnerabilities in IBM Security Verify Governance, Identity Manager virtual appliance component
- Multiple vulnerabilities in Dell EMC Unisphere for PowerMax and Dell EMC Solutions Enabler
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- F5 BIG-IP update for OpenJDK
- F5 BIG-IQ Centralized Management update for Java
- IBM Cloud Application Business Insights update for Java and WLP
- IBM Tivoli Monitoring update for IBM Java
- Red Hat Enterprise Linux 8 update for java-11-openjdk
- Red Hat Enterprise Linux 8.1 Extended Update Support update for java-11-openjdk
- Red Hat Enterprise Linux 7 update for java-11-openjdk
- Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions update for java-11-openjdk
- Missing encryption of sensitive data in IBM CICS TX on Cloud
- Missing Encryption of Sensitive Data in IBM Cloud Transformation Advisor
- Multiple vunerabilities in IBM Cloud Pak System
- Gentoo update for IcedTea
- Ubuntu update for openjdk-8
- Ubuntu update for openjdk-8
- Fedora 33 update for java-11-openjdk
- Fedora 32 update for java-11-openjdk
- Fedora 31 update for java-11-openjdk
- Fedora 33 update for java-1.8.0-openjdk
- Fedora 32 update for java-1.8.0-openjdk
- Fedora 31 update for java-1.8.0-openjdk
- RSA Authentication Manager update for third-party components