#VU47777 Missing Encryption of Sensitive Data in Java SE Embedded - CVE-2020-14781
Published: October 21, 2020 / Updated: March 20, 2022
Java SE Embedded
Oracle
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The vulnerability exists due to improper input validation within the JNDI component in Java SE Embedded when processing encrypted LDAP requests. A remote non-authenticated attacker can downgrade the encrypted LDAP connection and gain access to sensitive information.