CVE-2022-21626 is a vulnerability in Oracle Java SE and Oracle GraalVM Enterprise Edition, specifically affecting the Security component in versions 8u341, 8u345-perf, 11.0.16.1, 20.3.7, 21.3.3, and 22.2.0, respectively. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTPS to cause a partial denial of service. The CVSS 3.1 Base Score is 5.3 (Medium), indicating a low impact on availability. The attack vector is network-based with low attack complexity, requiring no user interaction or privileges. It primarily impacts Java deployments running sandboxed applications or applets that load untrusted code, or can be exploited through APIs supplying data. While the potential impact is limited to partial denial of service, it's a concern for environments relying on the Java sandbox for security. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting low public awareness and attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20.3.7CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm:20.3.7:*:*:*:enterprise:*:*:* | ||
21.3.3CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm:21.3.3:*:*:*:enterprise:*:*:* | ||
22.2.0CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm:22.2.0:*:*:*:enterprise:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update341:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update345:*:*:enterprise_performance_pack:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533)
Oct 18, 2022Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplie
Oct 11, 2022