Skip to main content
I have heard about a vulnerabiltity in Java depending ECDSA Signatures (Java Psychic Signatures CVE-2022-21449): My question is: Does Salesforce SSO use this ECDSA technic?
1 risposta
  1. 26 apr 2022, 10:19
    Salesforce does not comment specifically on every publicly reported software vulnerability or breach.

    If Salesforce were impacted by this announcement, salesforce would patch it per their established vulnerability remediation process.

    Salesforce regularly identifies and patches all vulnerabilities in a timely manner per their vulnerability management process.

    See https://help.salesforce.com/s/articleView?id=000365020&type=1

    https://status.salesforce.com/generalmessages/884

    Security Vulnerability Finding Submittal Guide:

    https://help.salesforce.com/s/articleView?id=000320207&type=1

    If this information helps, please mark the answer as best. Thank you
0/9000