CVE-2022-21619Integer Coercion Error in Corporation Java SE JDK AND JRE

Severity
3.7LOWNVD
OSV5.3
EPSS
0.3%
top 50.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 18
Latest updateNov 9

Description

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability c

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 2.2 | Impact: 1.4

Affected Packages6 packages

NVDoracle/graalvm20.3.7, 21.3.3, 22.2.0+2
NVDoracle/jdk4 versions+3
NVDoracle/jre4 versions+3

Also affects: Fedora 35, 36

Patches

🔴Vulnerability Details

4
OSV
openjdk-8, openjdk-lts, openjdk-17, openjdk-19 vulnerabilities2022-11-09
GHSA
GHSA-3ggq-p922-54qp: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security)2022-10-19
CVEList
CVE-2022-21619: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security)2022-10-18
OSV
CVE-2022-21619: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security)2022-10-18

📋Vendor Advisories

5
Ubuntu
OpenJDK vulnerabilities2022-11-09
Red Hat
OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526)2022-10-18
Oracle
Oracle Oracle Java SE Risk Matrix: Security — CVE-2022-216192022-10-15
Microsoft
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.02022-10-11
Debian
CVE-2022-21619: openjdk-11 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...2022
CVE-2022-21619 — Integer Coercion Error | cvebase