cbcvebase.
CVE-2022-21449
published 2022-04-19

CVE-2022-21449: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected…

PriorityP263high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
48.23%
98.7th percentile
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.2 and 18; Oracle GraalVM Enterprise Edition: 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

Affected

16 ranges
VendorProductVersion rangeFixed in
azulzulu
azulzulu
azulzulu
debiandebian_linux
debiandebian_linux
debianopenjdk-17< openjdk-17 17.0.3+7-1 (bookworm)openjdk-17 17.0.3+7-1 (bookworm)
netappe-series_santricity_os_controller
oraclegraalvm
oraclegraalvm
oraclejdk
oraclejdk
oracle_corporationjava_se_jdk_and_jre
oracle_corporationjava_se_jdk_and_jre
oracle_corporationjava_se_jdk_and_jre
oracle_corporationjava_se_jdk_and_jre
paloaltopan-os

Detection & IOCsextracted from sources · hover to see the quote

otherMAYCAQACAQA
othereyJhbGciOiJFUzI1NiJ9.<base64(payload)>.MAYCAQACAQA
versionio.jsonwebtoken:jjwt-api:0.11.2
  • CVE-2022-21449 ('Psychic Signatures') allows ECDSA signature bypass in Java 17/18 and GraalVM 21.3.1/22.0.0.2. An attacker can forge a valid ES256 JWT by supplying a blank/zeroed DER-encoded ECDSA signature (e.g., MAYCAQACAQA in base64url). Detect JWT tokens where the signature component decodes to a near-zero or all-zero DER ECDSA structure (r=0, s=0 or r=1, s=1).
  • Affected Oracle Java SE versions: 17.0.2 and 18; Oracle GraalVM Enterprise Edition: 21.3.1 and 22.0.0.2. Flag deployments running these JVM versions using ECDSA signature verification (e.g., ES256/ES384/ES512 JWT algorithms) as high-priority patching targets.
  • The vulnerability is in the Libraries component (bug 8277233) of Oracle Java SE. Inspect ECDSA signature verification code paths in Java 17/18 for missing or improper validation of r and s values in the signature.
  • ·The vulnerability can be exploited both via sandboxed Java Web Start/applet contexts AND directly through APIs (e.g., web services supplying data to the Libraries API), broadening the attack surface beyond browser-based deployments.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.