CVE-2022-21283

Severity

53%

Complexity

39%

Confidentiality

23%

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVSS 3.1 Base Score 5.3. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVSS 2.0 Base Score 5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).

Overview

First reported 3 years ago

2022-01-19 12:15:00

Last updated 2 years ago

2022-10-27 22:55:00

Affected Software

Netapp Cloud Insights

NetApp E-Series SANtricity OS Controller

Debian Linux 9.0

9.0

Oracle OpenJDK 8

8

Oracle OpenJDK 8 Update 102

8

Oracle OpenJDK 8 Update 112

8

Oracle OpenJDK 8 Update 152

8

Oracle OpenJDK 8 Update 162

8

Oracle OpenJDK 8 Update 172

8

Oracle OpenJDK 8 Update 192

8

Oracle OpenJDK 8 Update 20

8

Oracle OpenJDK 8 Update 202

8

Oracle OpenJDK 8 Update 212

8

Oracle OpenJDK 7

7

Oracle OpenJDK 7 Update 241

7

Oracle OpenJDK 7 Update 80

7

Oracle OpenJDK 7 Update 85

7

Oracle OpenJDK 8 Update 222

8

Oracle OpenJDK 8 Update 232

8

Oracle OpenJDK 8 Update 40

8

Oracle OpenJDK 8 Update 60

8

Oracle OpenJDK 8 Update 66

8

Oracle OpenJDK 8 Update 72

8

Oracle OpenJDK 8 Update 92

8

Oracle OpenJDK 8 Milestone 1

8

Oracle OpenJDK 8 Milestone 2

8

Oracle OpenJDK 8 Milestone 3

8

Oracle OpenJDK 8 Milestone 4

8

Oracle OpenJDK 8 Milestone 5

8

Oracle OpenJDK 8 Milestone 6

8

Oracle OpenJDK 8 Milestone 7

8

Oracle OpenJDK 8 Milestone 8

8

Oracle OpenJDK 8 Milestone 9

8

Oracle OpenJDK 8 Update 242

8

Oracle OpenJDK 8 Update 252

8

Oracle OpenJDK 8 Update 262

8

Oracle OpenJDK -

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.