CVE-2023-22067
published 2023-10-17CVE-2023-22067: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Supported versions that are affected are…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.89%
55.6th percentile
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf; Oracle GraalVM Enterprise Edition: 20.3.11 and 21.3.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via CORBA to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | < openjdk-8 8u392-ga-1 (sid) | openjdk-8 8u392-ga-1 (sid) |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle_corporation | java_se_jdk_and_jre | — | — |
| oracle_corporation | java_se_jdk_and_jre | — | — |
| oracle_corporation | java_se_jdk_and_jre | — | — |
| oracle_corporation | java_se_jdk_and_jre | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2023-11-29·CVSS 3.7
CVE-2023-22067 [LOW] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
It was discovered that the HotSpot VM implementation in OpenJDK did not
properly validate bytecode blocks in certain situations. An attacker could
possibly use this to cause a denial of service. (CVE-2022-40433)
Carter Kozak discovered that OpenJDK, when compiling with AVX-512
instruction support enabled, could produce code that resulted in memory
corruption in certain situations. An attacker targeting applications built
in this way could possibly use this to cause a denial of service or execute
arbitrary code. In Ubuntu, OpenJDK defaults to not using AVX-512
instructions. (CVE-2023-22025)
It was discovered that the CORBA implementation in OpenJDK did not properly
perform deserialization of IOR str
Red Hat
OpenJDK: IOR deserialization issue in CORBA (8303384)
vendor_redhat·2023-10-17·CVSS 5.3
CVE-2023-22067 [MEDIUM] CWE-502 OpenJDK: IOR deserialization issue in CORBA (8303384)
OpenJDK: IOR deserialization issue in CORBA (8303384)
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf; Oracle GraalVM Enterprise Edition: 20.3.11 and 21.3.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via CORBA to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untr
Oracle
Oracle Oracle Java SE Risk Matrix: CORBA — CVE-2023-22067
vendor_oracle·2023-10-15·CVSS 5.3
CVE-2023-22067 [MEDIUM] Oracle Oracle Java SE Risk Matrix: CORBA — CVE-2023-22067
Oracle Oracle Java SE Risk Matrix: CORBA vulnerability
CVE: CVE-2023-22067
CVSS: 5.3
Protocol: CORBA
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Debian
CVE-2023-22067: openjdk-8 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...
vendor_debian·2023·CVSS 5.3
CVE-2023-22067 [MEDIUM] CVE-2023-22067: openjdk-8 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf; Oracle GraalVM Enterprise Edition: 20.3.11 and 21.3.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via CORBA to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS
OSV
openjdk-8 vulnerabilities
osv·2023-11-29·CVSS 3.7
CVE-2022-40433 [LOW] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
It was discovered that the HotSpot VM implementation in OpenJDK did not
properly validate bytecode blocks in certain situations. An attacker could
possibly use this to cause a denial of service. (CVE-2022-40433)
Carter Kozak discovered that OpenJDK, when compiling with AVX-512
instruction support enabled, could produce code that resulted in memory
corruption in certain situations. An attacker targeting applications built
in this way could possibly use this to cause a denial of service or execute
arbitrary code. In Ubuntu, OpenJDK defaults to not using AVX-512
instructions. (CVE-2023-22025)
It was discovered that the CORBA implementation in OpenJDK did not properly
perform deserialization of IOR string objects. An attacker could possibly
use this to bypass Java
GHSA
GHSA-h8rm-272h-gc9p: Vulnerability in Oracle Java SE (component: CORBA)
ghsa_unreviewed·2023-10-18
CVE-2023-22067 [MEDIUM] CWE-863 GHSA-h8rm-272h-gc9p: Vulnerability in Oracle Java SE (component: CORBA)
Vulnerability in Oracle Java SE (component: CORBA). Supported versions that are affected are Oracle Java SE: 8u381 and 8u381-perf. Easily exploitable vulnerability allows unauthenticated attacker with network access via CORBA to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
OSV
CVE-2023-22067: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA)
osv·2023-10-17·CVSS 5.3
CVE-2023-22067 [MEDIUM] CVE-2023-22067: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA)
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf; Oracle GraalVM Enterprise Edition: 20.3.11 and 21.3.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via CORBA to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://security.netapp.com/advisory/ntap-20231027-0006/https://www.debian.org/security/2023/dsa-5537https://www.oracle.com/security-alerts/cpuoct2023.htmlhttps://security.netapp.com/advisory/ntap-20231027-0006/https://security.netapp.com/advisory/ntap-20241108-0002/https://www.debian.org/security/2023/dsa-5537https://www.oracle.com/security-alerts/cpuoct2023.html
2023-10-17
Published