CVE-2020-2778
Summary
| CVE | CVE-2020-2778 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-15 14:15:00 UTC |
| Updated | 2022-10-14 18:33:00 UTC |
| Description | Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.10 | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Application | Netapp | 7-mode Transition Tool | - | All | All | All |
| Application | Netapp | Active Iq Unified Manager | All | All | All | All |
| Application | Netapp | Active Iq Unified Manager | All | All | All | All |
| Application | Netapp | Active Iq Unified Manager | - | All | All | All |
| Application | Netapp | Active Iq Unified Manager | - | All | All | All |
| Application | Netapp | Active Iq Unified Manager | All | All | All | All |
| Application | Netapp | Active Iq Unified Manager | All | All | All | All |
| Application | Netapp | Cloud Backup | - | All | All | All |
| Application | Netapp | Cloud Secure Agent | - | All | All | All |
| Application | Netapp | E-series Performance Analyzer | - | All | All | All |
| Application | Netapp | E-series Santricity Os Controller | All | All | All | All |
| Application | Netapp | E-series Santricity Os Controller | All | All | All | All |
| Application | Netapp | E-series Santricity Web Services | - | All | All | All |
| Application | Netapp | Oncommand Insight | - | All | All | All |
| Application | Netapp | Oncommand Workflow Automation | - | All | All | All |
| Application | Netapp | Plug-in For Symantec Netbackup | - | All | All | All |
| Application | Netapp | Santricity Unified Manager | - | All | All | All |
| Application | Netapp | Snapmanager | - | All | All | All |
| Application | Netapp | Snapmanager | - | - | All | All |
| Application | Netapp | Snapmanager | - | All | All | All |
| Application | Netapp | Snapmanager | - | - | All | All |
| Application | Netapp | Steelstore Cloud Integrated Storage | - | All | All | All |
| Application | Netapp | Storagegrid | - | All | All | All |
| Application | Netapp | Storagegrid | - | All | All | All |
| Application | Netapp | Storagegrid | All | All | All | All |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
| Application | Oracle | Jdk | 11.0.6 | All | All | All |
| Application | Oracle | Jdk | 14.0.0 | All | All | All |
| Application | Oracle | Jdk | 11.0.6 | All | All | All |
| Application | Oracle | Jdk | 14.0.0 | All | All | All |
| Application | Oracle | Jre | 11.0.6 | All | All | All |
| Application | Oracle | Jre | 14.0.0 | All | All | All |
| Application | Oracle | Jre | 11.0.6 | All | All | All |
| Application | Oracle | Jre | 14.0.0 | All | All | All |
| Application | Oracle | Openjdk | 14 | All | All | All |
| Application | Oracle | Openjdk | 7 | - | All | All |
| Application | Oracle | Openjdk | 7 | update1 | All | All |
| Application | Oracle | Openjdk | 7 | update10 | All | All |
| Application | Oracle | Openjdk | 7 | update101 | All | All |
| Application | Oracle | Openjdk | 7 | update11 | All | All |
| Application | Oracle | Openjdk | 7 | update111 | All | All |
| Application | Oracle | Openjdk | 7 | update121 | All | All |
| Application | Oracle | Openjdk | 7 | update13 | All | All |
| Application | Oracle | Openjdk | 7 | update131 | All | All |
| Application | Oracle | Openjdk | 7 | update141 | All | All |
| Application | Oracle | Openjdk | 7 | update15 | All | All |
| Application | Oracle | Openjdk | 7 | update151 | All | All |
| Application | Oracle | Openjdk | 7 | update161 | All | All |
| Application | Oracle | Openjdk | 7 | update17 | All | All |
| Application | Oracle | Openjdk | 7 | update171 | All | All |
| Application | Oracle | Openjdk | 7 | update181 | All | All |
| Application | Oracle | Openjdk | 7 | update191 | All | All |
| Application | Oracle | Openjdk | 7 | update2 | All | All |
| Application | Oracle | Openjdk | 7 | update201 | All | All |
| Application | Oracle | Openjdk | 7 | update21 | All | All |
| Application | Oracle | Openjdk | 7 | update211 | All | All |
| Application | Oracle | Openjdk | 7 | update221 | All | All |
| Application | Oracle | Openjdk | 7 | update231 | All | All |
| Application | Oracle | Openjdk | 7 | update241 | All | All |
| Application | Oracle | Openjdk | 7 | update25 | All | All |
| Application | Oracle | Openjdk | 7 | update251 | All | All |
| Application | Oracle | Openjdk | 7 | update3 | All | All |
| Application | Oracle | Openjdk | 7 | update4 | All | All |
| Application | Oracle | Openjdk | 7 | update40 | All | All |
| Application | Oracle | Openjdk | 7 | update45 | All | All |
| Application | Oracle | Openjdk | 7 | update5 | All | All |
| Application | Oracle | Openjdk | 7 | update51 | All | All |
| Application | Oracle | Openjdk | 7 | update55 | All | All |
| Application | Oracle | Openjdk | 7 | update6 | All | All |
| Application | Oracle | Openjdk | 7 | update60 | All | All |
| Application | Oracle | Openjdk | 7 | update65 | All | All |
| Application | Oracle | Openjdk | 7 | update67 | All | All |
| Application | Oracle | Openjdk | 7 | update7 | All | All |
| Application | Oracle | Openjdk | 7 | update72 | All | All |
| Application | Oracle | Openjdk | 7 | update76 | All | All |
| Application | Oracle | Openjdk | 7 | update80 | All | All |
| Application | Oracle | Openjdk | 7 | update85 | All | All |
| Application | Oracle | Openjdk | 7 | update9 | All | All |
| Application | Oracle | Openjdk | 7 | update91 | All | All |
| Application | Oracle | Openjdk | 7 | update95 | All | All |
| Application | Oracle | Openjdk | 7 | update97 | All | All |
| Application | Oracle | Openjdk | 7 | update99 | All | All |
| Application | Oracle | Openjdk | 8 | - | All | All |
| Application | Oracle | Openjdk | 8 | update101 | All | All |
| Application | Oracle | Openjdk | 8 | update102 | All | All |
| Application | Oracle | Openjdk | 8 | update11 | All | All |
| Application | Oracle | Openjdk | 8 | update111 | All | All |
| Application | Oracle | Openjdk | 8 | update112 | All | All |
| Application | Oracle | Openjdk | 8 | update121 | All | All |
| Application | Oracle | Openjdk | 8 | update131 | All | All |
| Application | Oracle | Openjdk | 8 | update141 | All | All |
| Application | Oracle | Openjdk | 8 | update151 | All | All |
| Application | Oracle | Openjdk | 8 | update152 | All | All |
| Application | Oracle | Openjdk | 8 | update161 | All | All |
| Application | Oracle | Openjdk | 8 | update162 | All | All |
| Application | Oracle | Openjdk | 8 | update171 | All | All |
| Application | Oracle | Openjdk | 8 | update172 | All | All |
| Application | Oracle | Openjdk | 8 | update181 | All | All |
| Application | Oracle | Openjdk | 8 | update191 | All | All |
| Application | Oracle | Openjdk | 8 | update192 | All | All |
| Application | Oracle | Openjdk | 8 | update20 | All | All |
| Application | Oracle | Openjdk | 8 | update201 | All | All |
| Application | Oracle | Openjdk | 8 | update202 | All | All |
| Application | Oracle | Openjdk | 8 | update211 | All | All |
| Application | Oracle | Openjdk | 8 | update212 | All | All |
| Application | Oracle | Openjdk | 8 | update221 | All | All |
| Application | Oracle | Openjdk | 8 | update231 | All | All |
| Application | Oracle | Openjdk | 8 | update241 | All | All |
| Application | Oracle | Openjdk | 8 | update25 | All | All |
| Application | Oracle | Openjdk | 8 | update31 | All | All |
| Application | Oracle | Openjdk | 8 | update40 | All | All |
| Application | Oracle | Openjdk | 8 | update45 | All | All |
| Application | Oracle | Openjdk | 8 | update5 | All | All |
| Application | Oracle | Openjdk | 8 | update51 | All | All |
| Application | Oracle | Openjdk | 8 | update60 | All | All |
| Application | Oracle | Openjdk | 8 | update65 | All | All |
| Application | Oracle | Openjdk | 8 | update66 | All | All |
| Application | Oracle | Openjdk | 8 | update71 | All | All |
| Application | Oracle | Openjdk | 8 | update72 | All | All |
| Application | Oracle | Openjdk | 8 | update73 | All | All |
| Application | Oracle | Openjdk | 8 | update74 | All | All |
| Application | Oracle | Openjdk | 8 | update77 | All | All |
| Application | Oracle | Openjdk | 8 | update91 | All | All |
| Application | Oracle | Openjdk | 8 | update92 | All | All |
| Application | Oracle | Openjdk | 14 | All | All | All |
| Application | Oracle | Openjdk | 7 | - | All | All |
| Application | Oracle | Openjdk | 7 | update1 | All | All |
| Application | Oracle | Openjdk | 7 | update10 | All | All |
| Application | Oracle | Openjdk | 7 | update101 | All | All |
| Application | Oracle | Openjdk | 7 | update11 | All | All |
| Application | Oracle | Openjdk | 7 | update111 | All | All |
| Application | Oracle | Openjdk | 7 | update121 | All | All |
| Application | Oracle | Openjdk | 7 | update13 | All | All |
| Application | Oracle | Openjdk | 7 | update131 | All | All |
| Application | Oracle | Openjdk | 7 | update141 | All | All |
| Application | Oracle | Openjdk | 7 | update15 | All | All |
| Application | Oracle | Openjdk | 7 | update151 | All | All |
| Application | Oracle | Openjdk | 7 | update161 | All | All |
| Application | Oracle | Openjdk | 7 | update17 | All | All |
| Application | Oracle | Openjdk | 7 | update171 | All | All |
| Application | Oracle | Openjdk | 7 | update181 | All | All |
| Application | Oracle | Openjdk | 7 | update191 | All | All |
| Application | Oracle | Openjdk | 7 | update2 | All | All |
| Application | Oracle | Openjdk | 7 | update201 | All | All |
| Application | Oracle | Openjdk | 7 | update21 | All | All |
| Application | Oracle | Openjdk | 7 | update211 | All | All |
| Application | Oracle | Openjdk | 7 | update221 | All | All |
| Application | Oracle | Openjdk | 7 | update231 | All | All |
| Application | Oracle | Openjdk | 7 | update241 | All | All |
| Application | Oracle | Openjdk | 7 | update25 | All | All |
| Application | Oracle | Openjdk | 7 | update251 | All | All |
| Application | Oracle | Openjdk | 7 | update3 | All | All |
| Application | Oracle | Openjdk | 7 | update4 | All | All |
| Application | Oracle | Openjdk | 7 | update40 | All | All |
| Application | Oracle | Openjdk | 7 | update45 | All | All |
| Application | Oracle | Openjdk | 7 | update5 | All | All |
| Application | Oracle | Openjdk | 7 | update51 | All | All |
| Application | Oracle | Openjdk | 7 | update55 | All | All |
| Application | Oracle | Openjdk | 7 | update6 | All | All |
| Application | Oracle | Openjdk | 7 | update60 | All | All |
| Application | Oracle | Openjdk | 7 | update65 | All | All |
| Application | Oracle | Openjdk | 7 | update67 | All | All |
| Application | Oracle | Openjdk | 7 | update7 | All | All |
| Application | Oracle | Openjdk | 7 | update72 | All | All |
| Application | Oracle | Openjdk | 7 | update76 | All | All |
| Application | Oracle | Openjdk | 7 | update80 | All | All |
| Application | Oracle | Openjdk | 7 | update85 | All | All |
| Application | Oracle | Openjdk | 7 | update9 | All | All |
| Application | Oracle | Openjdk | 7 | update91 | All | All |
| Application | Oracle | Openjdk | 7 | update95 | All | All |
| Application | Oracle | Openjdk | 7 | update97 | All | All |
| Application | Oracle | Openjdk | 7 | update99 | All | All |
| Application | Oracle | Openjdk | 8 | - | All | All |
| Application | Oracle | Openjdk | 8 | update101 | All | All |
| Application | Oracle | Openjdk | 8 | update102 | All | All |
| Application | Oracle | Openjdk | 8 | update11 | All | All |
| Application | Oracle | Openjdk | 8 | update111 | All | All |
| Application | Oracle | Openjdk | 8 | update112 | All | All |
| Application | Oracle | Openjdk | 8 | update121 | All | All |
| Application | Oracle | Openjdk | 8 | update131 | All | All |
| Application | Oracle | Openjdk | 8 | update141 | All | All |
| Application | Oracle | Openjdk | 8 | update151 | All | All |
| Application | Oracle | Openjdk | 8 | update152 | All | All |
| Application | Oracle | Openjdk | 8 | update161 | All | All |
| Application | Oracle | Openjdk | 8 | update162 | All | All |
| Application | Oracle | Openjdk | 8 | update171 | All | All |
| Application | Oracle | Openjdk | 8 | update172 | All | All |
| Application | Oracle | Openjdk | 8 | update181 | All | All |
| Application | Oracle | Openjdk | 8 | update191 | All | All |
| Application | Oracle | Openjdk | 8 | update192 | All | All |
| Application | Oracle | Openjdk | 8 | update20 | All | All |
| Application | Oracle | Openjdk | 8 | update201 | All | All |
| Application | Oracle | Openjdk | 8 | update202 | All | All |
| Application | Oracle | Openjdk | 8 | update211 | All | All |
| Application | Oracle | Openjdk | 8 | update212 | All | All |
| Application | Oracle | Openjdk | 8 | update221 | All | All |
| Application | Oracle | Openjdk | 8 | update231 | All | All |
| Application | Oracle | Openjdk | 8 | update241 | All | All |
| Application | Oracle | Openjdk | 8 | update25 | All | All |
| Application | Oracle | Openjdk | 8 | update31 | All | All |
| Application | Oracle | Openjdk | 8 | update40 | All | All |
| Application | Oracle | Openjdk | 8 | update45 | All | All |
| Application | Oracle | Openjdk | 8 | update5 | All | All |
| Application | Oracle | Openjdk | 8 | update51 | All | All |
| Application | Oracle | Openjdk | 8 | update60 | All | All |
| Application | Oracle | Openjdk | 8 | update65 | All | All |
| Application | Oracle | Openjdk | 8 | update66 | All | All |
| Application | Oracle | Openjdk | 8 | update71 | All | All |
| Application | Oracle | Openjdk | 8 | update72 | All | All |
| Application | Oracle | Openjdk | 8 | update73 | All | All |
| Application | Oracle | Openjdk | 8 | update74 | All | All |
| Application | Oracle | Openjdk | 8 | update77 | All | All |
| Application | Oracle | Openjdk | 8 | update91 | All | All |
| Application | Oracle | Openjdk | 8 | update92 | All | All |
| Application | Oracle | Openjdk | All | All | All | All |
| Application | Oracle | Openjdk | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-4662-1 openjdk-11 | DEBIAN | www.debian.org | |
| Oracle Critical Patch Update Advisory - April 2020 | MISC | www.oracle.com | Vendor Advisory |
| April 2020 Java Platform Standard Edition Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | Third Party Advisory |
| [security-announce] openSUSE-SU-2020:0757-1: important: Security update | SUSE | lists.opensuse.org | |
| USN-4337-1: OpenJDK vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 373382 Azul Zing Multiple Vulnerabilities(java_apr2020_advisory)
- 375812 Azul Java Multiple Vulnerabilities Security Update April 2020
- 375981 Amazon Corretto Critical Patch Update (APR2020)
- 377220 Alibaba Cloud Linux Security Update for java-11-openjdk (ALINUX2-SA-2020:0091)
- 501204 Alpine Linux Security Update for openjdk11