CVE-2022-21628Allocation of Resources Without Limits or Throttling in Corporation Java SE JDK AND JRE

Severity
5.3MEDIUMNVD
EPSS
0.4%
top 39.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 18
Latest updateNov 9

Description

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability ca

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages6 packages

NVDoracle/graalvm20.3.7, 21.3.3, 22.2.0+2
NVDoracle/jdk4 versions+3
NVDoracle/jre4 versions+3

Also affects: Fedora 35, 36

Patches

🔴Vulnerability Details

4
OSV
openjdk-8, openjdk-lts, openjdk-17, openjdk-19 vulnerabilities2022-11-09
GHSA
GHSA-34g7-gffm-5gm5: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Lightweight HTTP Server)2022-10-19
CVEList
CVE-2022-21628: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Lightweight HTTP Server)2022-10-18
OSV
CVE-2022-21628: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Lightweight HTTP Server)2022-10-18

📋Vendor Advisories

5
Ubuntu
OpenJDK vulnerabilities2022-11-09
Red Hat
OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918)2022-10-18
Oracle
Oracle Oracle Java SE Risk Matrix: Lightweight HTTP Server — CVE-2022-216282022-10-15
Microsoft
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Oracle Java SE: 8u341, 82022-10-11
Debian
CVE-2022-21628: openjdk-11 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...2022
CVE-2022-21628 — MEDIUM severity | cvebase