Sat. May 28th, 2022

Oracle has patched a nasty vulnerability in the Java framework, the severity of which cannot be overstated, according to security experts.

Tracked as CVE-2022-21449, the flaw was discovered in the company’s Elliptic Curve Digital Signature Algorithm (ECDSA) for Java 15 and later. It allows threat actors to forge TSL certificates and signatures, two-factor authentication codes, authorization credentials, and more.

