> Source: [sk178887](https://support.checkpoint.com/results/sk/sk178887)

# sk178887 - Check Point Response to CVE-2022-21449 - Java "Psychic Signatures"

| Property | Value |
|----------|-------|
| Solution ID | sk178887 |
| Date Created | 2022-04-25 |
| Last Modified | 2025-02-09 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Cloud Firewall |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.10, R82, R81.20, R82.10, R81 (EOS), R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82 |

## Symptoms

- On April 20, 2022, security researcher Neil Madden published a [blog post](https://neilmadden.blog/2022/04/19/psychic-signatures-in-java/) in which he provided details about a newly disclosed vulnerability in Java, [CVE-2022-21449](https://www.cve.org/CVERecord?id=CVE-2022-21449) or "Psychic Signatures". This security vulnerability originates in an incorrect implementation of the ECDSA signature verification algorithm, introduced in Java 15.

## Solution

The Check Point Infinity architecture is protected against this threat. We verified that this vulnerability does not affect our Infinity portfolio (including Quantum Security Gateways, Smart Management, Quantum Spark appliances with Gaia Embedded OS, Harmony Endpoint, Harmony Mobile, ThreatCloud, and CloudGuard).

**Check Point Products Status**

|------------------------------------------------|--------------------|
| Product                                        | Status             |
| Quantum Security Gateway                       | **Not vulnerable** |
| Quantum Spark appliances with Gaia Embedded OS | **Not vulnerable** |
| Quantum Security Management                    | **Not vulnerable** |
| CloudGuard                                     | **Not vulnerable** |
| Infinity Portal                                | **Not vulnerable** |
| Harmony Endpoint \& Harmony Mobile             | **Not vulnerable** |
| Harmony Connect                                | **Not vulnerable** |
| ThreatCloud                                    | **Not vulnerable** |

**Notes:**

* All Check Point software versions, including out of support versions, are not vulnerable.
* All Check Point appliances are not vulnerable.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
