CVE-2023-22043
published 2023-07-18CVE-2023-22043: Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u371. Difficult to exploit vulnerability allows…
PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
1.14%
62.9th percentile
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u371. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjfx | < openjfx 11+26-1 (bookworm) | openjfx 11+26-1 (bookworm) |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle_corporation | java_se_jdk_and_jre | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_oracle5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Oracle Java SE) — CVE-2023-22043
vendor_oracle·2023-10-15·CVSS 5.9
CVE-2023-22043 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Oracle Java SE) — CVE-2023-22043
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Oracle Java SE) vulnerability
CVE: CVE-2023-22043
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Red Hat
JavaFX: unauthorized creation, deletion or modification access to critical data via multiple protocols
vendor_redhat·2023-07-18·CVSS 5.9
CVE-2023-22043 [MEDIUM] JavaFX: unauthorized creation, deletion or modification access to critical data via multiple protocols
JavaFX: unauthorized creation, deletion or modification access to critical data via multiple protocols
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u371. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This v
Oracle
Oracle Oracle Java SE Risk Matrix: JavaFX — CVE-2023-22043
vendor_oracle·2023-07-15·CVSS 5.9
CVE-2023-22043 [MEDIUM] Oracle Oracle Java SE Risk Matrix: JavaFX — CVE-2023-22043
Oracle Oracle Java SE Risk Matrix: JavaFX vulnerability
CVE: CVE-2023-22043
CVSS: 5.9
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Debian
CVE-2023-22043: openjfx - Vulnerability in Oracle Java SE (component: JavaFX). The supported version tha...
vendor_debian·2023·CVSS 5.9
CVE-2023-22043 [MEDIUM] CVE-2023-22043: openjfx - Vulnerability in Oracle Java SE (component: JavaFX). The supported version tha...
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u371. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted co
GHSA
GHSA-grjf-4ggg-f6cm: Vulnerability in Oracle Java SE (component: JavaFX)
ghsa_unreviewed·2023-07-18
CVE-2023-22043 [MEDIUM] GHSA-grjf-4ggg-f6cm: Vulnerability in Oracle Java SE (component: JavaFX)
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u371. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted co
OSV
CVE-2023-22043: Vulnerability in Oracle Java SE (component: JavaFX)
osv·2023-07-18·CVSS 5.9
CVE-2023-22043 [MEDIUM] CVE-2023-22043: Vulnerability in Oracle Java SE (component: JavaFX)
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u371. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted co
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-18
Published