CVE-2022-21426 is a partial denial-of-service vulnerability affecting Oracle Java SE (versions 7u331, 8u321, 11.0.14, 17.0.2, 18) and Oracle GraalVM Enterprise Edition (versions 20.3.5, 21.3.1, 22.0.0.2), specifically within the JAXP component. This easily exploitable vulnerability allows an unauthenticated attacker with network access to cause a partial denial of service. It primarily impacts Java deployments running untrusted code in sandboxed environments or through APIs supplying data to the affected component. The vulnerability has a CVSS 3.1 Base Score of 5.3 (Medium), indicating low impact on availability, with no impact on confidentiality or integrity. The attack vector is network-based, requires no privileges or user interaction, and has low attack complexity. Currently, there is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness or immediate concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20.3.5CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm:20.3.5:*:*:*:enterprise:*:*:* | ||
21.3.1CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm:21.3.1:*:*:*:enterprise:*:*:* | ||
22.0.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm:22.0.0.2:*:*:*:enterprise:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update331:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update321:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.