CVE-2023-21835
published 2023-01-18CVE-2023-21835: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.84%
76.5th percentile
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.17, 17.0.5, 19.0.1; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via DTLS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| azul | zulu | — | — |
| azul | zulu | — | — |
| azul | zulu | — | — |
| azul | zulu | — | — |
| azul | zulu | — | — |
| debian | openjdk-11 | < openjdk-11 11.0.18+10-1~deb11u1 (bullseye) | openjdk-11 11.0.18+10-1~deb11u1 (bullseye) |
| debian | openjdk-17 | < openjdk-11 11.0.18+10-1~deb11u1 (bullseye) | openjdk-11 11.0.18+10-1~deb11u1 (bullseye) |
| debian | openjdk-21 | < openjdk-11 11.0.18+10-1~deb11u1 (bullseye) | openjdk-11 11.0.18+10-1~deb11u1 (bullseye) |
| oracle | graalvm | — | — |
| oracle | graalvm | — | — |
| oracle | graalvm | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle_corporation | java_se_jdk_and_jre | — | — |
| oracle_corporation | java_se_jdk_and_jre | — | — |
| oracle_corporation | java_se_jdk_and_jre | — | — |
| oracle_corporation | java_se_jdk_and_jre | — | — |
| oracle_corporation | java_se_jdk_and_jre | — | — |
| oracle_corporation | java_se_jdk_and_jre | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
openjdk-17, openjdk-19, openjdk-lts vulnerabilities
osv·2023-02-28·CVSS 5.3
CVE-2023-21835 [MEDIUM] openjdk-17, openjdk-19, openjdk-lts vulnerabilities
openjdk-17, openjdk-19, openjdk-lts vulnerabilities
Juraj Somorovsky, Marcel Maehren, Nurullah Erinola, and Robert Merget
discovered that the DTLS implementation in the JSSE subsystem of OpenJDK
did not properly restrict handshake initiation requests from clients. A
remote attacker could possibly use this to cause a denial of service.
(CVE-2023-21835)
Markus Loewe discovered that the Java Sound subsystem in OpenJDK did not
properly validate the origin of a Soundbank. An attacker could use this to
specially craft an untrusted Java application or applet that could load a
Soundbank from an attacker controlled remote URL. (CVE-2023-21843)
OSV
CVE-2023-21835: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE)
osv·2023-01-18·CVSS 5.3
CVE-2023-21835 [MEDIUM] CVE-2023-21835: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE)
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.17, 17.0.5, 19.0.1; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via DTLS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that co
GHSA
GHSA-wqgc-h828-9g98: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE)
ghsa_unreviewed·2023-01-18
CVE-2023-21835 [MEDIUM] GHSA-wqgc-h828-9g98: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE)
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.17, 17.0.5, 19.0.1; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via DTLS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that co
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2023-02-28·CVSS 5.3
CVE-2023-21843 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
Juraj Somorovsky, Marcel Maehren, Nurullah Erinola, and Robert Merget
discovered that the DTLS implementation in the JSSE subsystem of OpenJDK
did not properly restrict handshake initiation requests from clients. A
remote attacker could possibly use this to cause a denial of service.
(CVE-2023-21835)
Markus Loewe discovered that the Java Sound subsystem in OpenJDK did not
properly validate the origin of a Soundbank. An attacker could use this to
specially craft an untrusted Java application or applet that could load a
Soundbank from an attacker controlled remote URL. (CVE-2023-21843)
Instructions: This update uses a new upstream release, which includes additional
bug fixes. After a standard system up
Red Hat
OpenJDK: handshake DoS attack against DTLS connections (JSSE, 8287411)
vendor_redhat·2023-01-17·CVSS 5.3
CVE-2023-21835 [MEDIUM] CWE-400 OpenJDK: handshake DoS attack against DTLS connections (JSSE, 8287411)
OpenJDK: handshake DoS attack against DTLS connections (JSSE, 8287411)
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.17, 17.0.5, 19.0.1; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via DTLS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sand
Oracle
Oracle Oracle Java SE Risk Matrix: JSSE — CVE-2023-21835
vendor_oracle·2023-01-15·CVSS 5.3
CVE-2023-21835 [MEDIUM] Oracle Oracle Java SE Risk Matrix: JSSE — CVE-2023-21835
Oracle Oracle Java SE Risk Matrix: JSSE vulnerability
CVE: CVE-2023-21835
CVSS: 5.3
Protocol: DTLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Debian
CVE-2023-21835: openjdk-11 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...
vendor_debian·2023·CVSS 5.3
CVE-2023-21835 [MEDIUM] CVE-2023-21835: openjdk-11 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.17, 17.0.5, 19.0.1; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via DTLS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that co
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-18
Published