CVE-2021-2161

Severity

59%

Complexity

22%

Confidentiality

60%

Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM Enterprise Edition: 19.3.5, 20.3.1.2 and 21.0.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. It can also be exploited by supplying untrusted data to APIs in the specified Component. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVSS 3.1 Base Score 5.9. CVSS Attack Vector: network. CVSS Attack Complexity: high. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVSS 2.0 Base Score 4.3. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).

Overview

First reported 3 years ago

2021-04-22 22:15:00

Last updated 3 years ago

2021-12-08 20:08:00

Affected Software

Debian Linux 9.0

9.0

Fedora 32

32

Oracle OpenJDK 7

7

Oracle OpenJDK 7 Update 241

7

Oracle OpenJDK 8

8

Oracle OpenJDK 8 Update 102

8

Oracle OpenJDK 8 Update 112

8

Oracle OpenJDK 8 Update 152

8

Oracle OpenJDK 8 Update 162

8

Oracle OpenJDK 8 Update 172

8

Oracle OpenJDK 8 Update 192

8

Oracle OpenJDK 8 Update 20

8

Oracle OpenJDK 8 Update 202

8

Oracle OpenJDK 8 Update 212

8

Oracle OpenJDK 7 Update 80

7

Oracle OpenJDK 7 Update 85

7

Oracle OpenJDK 8 Milestone 1

8

Oracle OpenJDK 8 Milestone 2

8

Oracle OpenJDK 8 Milestone 3

8

Oracle OpenJDK 8 Milestone 4

8

Oracle OpenJDK 8 Milestone 5

8

Oracle OpenJDK 8 Milestone 6

8

Oracle OpenJDK 8 Milestone 7

8

Oracle OpenJDK 8 Milestone 8

8

Oracle OpenJDK 8 Milestone 9

8

Oracle OpenJDK 8 Update 222

8

Oracle OpenJDK 8 Update 232

8

Oracle OpenJDK 8 Update 40

8

Oracle OpenJDK 8 Update 60

8

Oracle OpenJDK 8 Update 66

8

Oracle OpenJDK 8 Update 72

8

Oracle OpenJDK 8 Update 92

8

Oracle OpenJDK 8 Update 242

8

Oracle OpenJDK 8 Update 252

8

Oracle OpenJDK 8 Update 262

8

Oracle OpenJDK -

NetApp Active IQ Unified Manager for VMware vSphere

vmware_vsphere

NetApp Active IQ Unified Manager for Windows

windows

McAfee ePolicy Orchestrator

McAfee ePolicy Orchestrator 5.10.0

5.10.0

McAfee ePolicy Orchestrator 5.10.0 Update 1

5.10.0

McAfee ePolicy Orchestrator 5.10.0 Update 2

5.10.0

McAfee ePolicy Orchestrator 5.10.0 Update 3

5.10.0

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.