Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-21349

21
FAUCET Score

CVE-2022-21349 is a vulnerability in Oracle Java SE (versions 7u321, 8u311) and Oracle GraalVM Enterprise Edition (versions 20.3.4, 21.3.0), specifically affecting the 2D component. This easily exploitable vulnerability allows an unauthenticated attacker with network access to cause a partial denial of service. With a CVSS score of 5.3 (Medium), it primarily impacts availability, particularly in Java deployments running sandboxed applications. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
20.3.4CPE matchmatch criteria
cpe:2.3:a:oracle:graalvm:20.3.4:*:*:*:enterprise:*:*:*
21.3.0CPE matchmatch criteria
cpe:2.3:a:oracle:graalvm:21.3.0:*:*:*:enterprise:*:*:*
1.7.0CPE matchmatch criteria
cpe:2.3:a:oracle:jdk:1.7.0:update321:*:*:*:*:*:*
1.8.0CPE matchmatch criteria
cpe:2.3:a:oracle:jdk:1.8.0:update311:*:*:*:*:*:*
1.7.0CPE matchmatch criteria
cpe:2.3:a:oracle:jre:1.7.0:update321:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.31%
Probability of exploitation in next 30 days
EPSS Percentile
87.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0331 is in the 83rd percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

microsoftpatch availablevia msrc
Product: 18804-16820Fixed in: -
microsoftpatch availablevia msrc
Product: cm1 openjdk8 1.8.0.332-1 on CBL Mariner 1.0Fixed in: -
oraclevendor investigatingvia nvd_reference
View patch

Vendor Advisories (2)

redhatCVE-2022-21349Low

OpenJDK: Unaligned memory access in ContextualGlyphSubstProc2 (2D, 8273748)

Jan 18, 2022
microsoft2022-Jan/CVE-2022-21349Moderate

Vulnerability in the Oracle Java SE Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u321 8u311; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments typically in clients running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code (e.g. code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component e.g. through a web service which supplies data to the APIs. CVSS 3

Jan 11, 2022

References

lists.debian.org / debian-lts-announce/2022/02/msg00011.html
Mailing ListThird Party Advisory
security.gentoo.org / glsa/202209-05
Third Party Advisory
security.netapp.com / advisory/ntap-20220121-0007
Third Party Advisory
oracle.com / security-alerts/cpujan2022.html
Vendor Advisory