3DES salt generation has a weakness when keys are repeated.
This CVE was fixed in Oracle Java SE 8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3. https://www.oracle.com/java/technologies/javase/8u491-relnotes.html#R180_491 https://www.oracle.com/java/technologies/javase/11-0-31-relnotes.html#R11_0_31 https://www.oracle.com/java/technologies/javase/17-0-19-relnotes.html#R17_0_19 https://www.oracle.com/java/technologies/javase/21-0-11-relnotes.html https://www.oracle.com/java/technologies/javase/25-0-3-relnotes.html
OpenJDK-8 upstream commit: https://github.com/openjdk/jdk8u/commit/b3af3d582429fcfff98e50fe434049b726d6acb5 OpenJDK-11 upstream commit: https://github.com/openjdk/jdk11u/commit/aa51a2af5fe9edd10ebfaf0b98a24e66025bfe73 OpenJDK-17 upstream commit: https://github.com/openjdk/jdk17u/commit/6927a870e22bb33ad36bc50dfc61ad55c38050db OpenJDK-21 upstream commit: https://github.com/openjdk/jdk21u/commit/00eba524bbb835cf6817c83026a70ea1e9919074 OpenJDK-25 upstream commit: https://github.com/openjdk/jdk25u/commit/f5d1128ebd099aae8b5ee615acee63cd49de47b2