It was discovered that the TLS implementation in the Security component of OpenJDK did not correctly handle CertificateVerify TLS handshake message received unexpectedly. A remote attacker attacker could use this flaw to affect confidentiality or integrity of a TLS connection.