CVE-2022-21541

Severity
5.9MEDIUM
EPSS
0.4%
top 39.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 19
Latest updateAug 4

Description

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability c

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages8 packages

NVDoracle/graalvm20.3.6, 21.3.2, 22.1.0+2
NVDoracle/openjdk1111.0.15+6
NVDoracle/jdk5 versions+4
NVDoracle/jre5 versions+4

Also affects: Debian Linux 10.0, 11.0, Fedora 36

Patches

🔴Vulnerability Details

3
GHSA
GHSA-vrhf-cc97-jx2x: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot)2022-07-20
CVEList
CVE-2022-21541: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot)2022-07-19
OSV
CVE-2022-21541: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot)2022-07-19

📋Vendor Advisories

6
Ubuntu
OpenJDK 8 vulnerabilities2022-08-04
Ubuntu
OpenJDK vulnerabilities2022-08-04
Red Hat
OpenJDK: improper restriction of MethodHandle.invokeBasic() (Hotspot, 8281866)2022-07-19
Oracle
Oracle Oracle Java SE Risk Matrix: Hotspot — CVE-2022-215412022-07-15
Microsoft
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1,2022-07-12