CVE-2022-21294

EUVD-2022-26519
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
oracleCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
Affected Products (NVD)
VendorProductVersion
oraclegraalvm
20.3.4
oraclegraalvm
21.3.0
oraclejdk
1.7.0
oraclejdk
1.8.0
oraclejdk
11.0.13
oraclejdk
17.0.1
oraclejre
1.7.0
oraclejre
1.8.0
oraclejre
11.0.13
oraclejre
17.0.1
netapp7-mode_transition_tool
-
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netappcloud_insights_acquisition_unit
-
netappcloud_secure_agent
-
netappe-series_santricity_os_controller
11.0.0 ≤
𝑥
≤ 11.70.1
netappe-series_santricity_storage_manager
-
netappe-series_santricity_web_services
-
netapphci_management_node
-
netapponcommand_insight
-
netapponcommand_workflow_automation
-
netappsantricity_storage_plugin
-
netappsantricity_unified_manager
-
netappsnapmanager
-
netappsnapmanager
-
netappsolidfire
-
debiandebian_linux
9.0
debiandebian_linux
10.0
debiandebian_linux
11.0
oracleopenjdk
11 ≤
𝑥
≤ 11.0.13
oracleopenjdk
13 ≤
𝑥
≤ 13.0.9
oracleopenjdk
15 ≤
𝑥
≤ 15.0.5
oracleopenjdk
17.0.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openjdk-11
102
105
102
105
102
105
openjdk-17
102
105
102
105
102
105
102
105
102
105
102
105
openjdk-8
102
105
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
icedtea-web
110
101
110
101
105
103
105
103
110
101
105
103
105
103
105
103
110
101
100
110
110
101
openjdk-12
100
110
100
110
100
110
100
110
100
110
100
110
100
110
100
110
100
110
100
110
100
110
openjdk-13
100
110
105
103
100
110
100
110
100
110
100
110
100
110
100
110
100
110
100
110
100
110
openjdk-15
100
110
100
110
105
103
100
110
100
110
100
110
100
110
100
110
100
110
100
110
100
110
openjdk-16
100
110
105
103
105
103
105
103
100
110
100
110
100
110
100
110
100
110
100
110
100
110
openjdk-17
114
101
114
101
105
103
114
101
110
111
110
111
110
111
110
111
110
111
100
110
100
110
openjdk-18
100
110
100
110
100
110
105
103
105
103
105
103
105
103
100
110
100
110
100
110
100
110
openjdk-8
114
101
114
101
105
103
105
103
114
101
110
111
110
111
110
111
110
111
100
110
114
101
openjdk-9
100
110
100
110
100
110
100
110
100
110
100
110
100
110
100
110
100
110
100
110
105
103
openjdk-lts
114
101
114
101
105
103
114
101
110
111
110
111
110
111
110
111
110
111
100
110
100
110