Bug 1198671 (CVE-2022-21476)

Summary: VUL-0: CVE-2022-21476: java-1_7_0-openjdk,java-1_8_0-openjdk,java-11-openjdk,java-17-openjdk: unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE
Product: [Novell Products] SUSE Security Incidents Reporter: Alexander Bergmann <abergmann>
Component: IncidentsAssignee: Fridrich Strba <fstrba>
Status: NEW --- QA Contact: Security Team bot <security-team>
Severity: Major    
Priority: P3 - Medium CC: fstrba, gabriele.sonnu, meissner, rfrohl, smash_bz, stoyan.manolov, thomas.leroy
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/329582/
Whiteboard: CVSSv3.1:SUSE:CVE-2022-21476:7.5:(AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Alexander Bergmann 2022-04-20 07:16:38 UTC
CVE-2022-21476

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product
of Oracle Java SE (component: Libraries). Supported versions that are affected
are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise
Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows
unauthenticated attacker with network access via multiple protocols to
compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks
of this vulnerability can result in unauthorized access to critical data or
complete access to all Oracle Java SE, Oracle GraalVM Enterprise Edition
accessible data. Note: This vulnerability applies to Java deployments, typically
in clients running sandboxed Java Web Start applications or sandboxed Java
applets, that load and run untrusted code (e.g., code that comes from the
internet) and rely on the Java sandbox for security. This vulnerability can also
be exploited by using APIs in the specified Component, e.g., through a web
service which supplies data to the APIs. CVSS 3.1 Base Score 7.5
(Confidentiality impacts). CVSS Vector:
(CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-21476
https://www.oracle.com/security-alerts/cpuapr2022.html#CVE-2022-21476
https://www.oracle.com/security-alerts/cpuapr2022.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21476
Comment 2 Swamp Workflow Management 2022-04-29 19:20:54 UTC
SUSE-SU-2022:1474-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1198671,1198672,1198673,1198674,1198675
CVE References: CVE-2022-21426,CVE-2022-21434,CVE-2022-21443,CVE-2022-21476,CVE-2022-21496
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP5 (src):    java-11-openjdk-11.0.15.0-3.43.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 3 Swamp Workflow Management 2022-05-03 19:21:19 UTC
SUSE-SU-2022:1513-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1198671,1198672,1198673,1198674,1198675
CVE References: CVE-2022-21426,CVE-2022-21434,CVE-2022-21443,CVE-2022-21476,CVE-2022-21496
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
openSUSE Leap 15.3 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Manager Server 4.1 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Manager Retail Branch Server 4.1 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Manager Proxy 4.1 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Server for SAP 15 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Server 15-SP2-BCL (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Server 15-LTSS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Realtime Extension 15-SP2 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Module for Basesystem 15-SP4 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Enterprise Storage 7 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Enterprise Storage 6 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE CaaS Platform 4.0 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2022-07-22 19:19:22 UTC
SUSE-SU-2022:2531-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1198671,1198672,1198673,1198674,1198675
CVE References: CVE-2022-21426,CVE-2022-21434,CVE-2022-21443,CVE-2022-21476,CVE-2022-21496
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    java-1_8_0-openjdk-1.8.0.332-27.75.2
SUSE OpenStack Cloud 9 (src):    java-1_8_0-openjdk-1.8.0.332-27.75.2
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    java-1_8_0-openjdk-1.8.0.332-27.75.2
SUSE Linux Enterprise Server 12-SP5 (src):    java-1_8_0-openjdk-1.8.0.332-27.75.2
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    java-1_8_0-openjdk-1.8.0.332-27.75.2
SUSE Linux Enterprise Server 12-SP3-BCL (src):    java-1_8_0-openjdk-1.8.0.332-27.75.2
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_8_0-openjdk-1.8.0.332-27.75.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2022-07-22 19:20:55 UTC
SUSE-SU-2022:2530-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1198671,1198672,1198673,1198674,1198675
CVE References: CVE-2022-21426,CVE-2022-21434,CVE-2022-21443,CVE-2022-21476,CVE-2022-21496
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
openSUSE Leap 15.3 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Manager Server 4.1 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Manager Retail Branch Server 4.1 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Manager Proxy 4.1 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Server for SAP 15 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Server 15-LTSS (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Module for Legacy Software 15-SP4 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Module for Legacy Software 15-SP3 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Enterprise Storage 7 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Enterprise Storage 6 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE CaaS Platform 4.0 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Swamp Workflow Management 2022-07-23 16:16:01 UTC
SUSE-SU-2022:2539-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1191912,1194931,1198670,1198671,1198672,1198673,1198674,1198675,1201643
CVE References: CVE-2021-35561,CVE-2022-21299,CVE-2022-21426,CVE-2022-21434,CVE-2022-21443,CVE-2022-21449,CVE-2022-21476,CVE-2022-21496
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    java-1_7_1-ibm-1.7.1_sr5.10-38.71.1
SUSE OpenStack Cloud 9 (src):    java-1_7_1-ibm-1.7.1_sr5.10-38.71.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    java-1_7_1-ibm-1.7.1_sr5.10-38.71.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    java-1_7_1-ibm-1.7.1_sr5.10-38.71.1
SUSE Linux Enterprise Server 12-SP5 (src):    java-1_7_1-ibm-1.7.1_sr5.10-38.71.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    java-1_7_1-ibm-1.7.1_sr5.10-38.71.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    java-1_7_1-ibm-1.7.1_sr5.10-38.71.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_7_1-ibm-1.7.1_sr5.10-38.71.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 11 Swamp Workflow Management 2022-07-23 16:17:31 UTC
SUSE-SU-2022:2540-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1191912,1194931,1198670,1198671,1198672,1198673,1198674,1198675,1201643
CVE References: CVE-2021-35561,CVE-2022-21299,CVE-2022-21426,CVE-2022-21434,CVE-2022-21443,CVE-2022-21449,CVE-2022-21476,CVE-2022-21496
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    java-1_8_0-ibm-1.8.0_sr7.10-30.90.1
SUSE OpenStack Cloud 9 (src):    java-1_8_0-ibm-1.8.0_sr7.10-30.90.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    java-1_8_0-ibm-1.8.0_sr7.10-30.90.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    java-1_8_0-ibm-1.8.0_sr7.10-30.90.1
SUSE Linux Enterprise Server 12-SP5 (src):    java-1_8_0-ibm-1.8.0_sr7.10-30.90.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    java-1_8_0-ibm-1.8.0_sr7.10-30.90.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    java-1_8_0-ibm-1.8.0_sr7.10-30.90.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_8_0-ibm-1.8.0_sr7.10-30.90.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Swamp Workflow Management 2022-08-03 16:23:59 UTC
SUSE-SU-2022:2650-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1191912,1194931,1198670,1198671,1198672,1198673,1198674,1198675,1201643
CVE References: CVE-2021-35561,CVE-2022-21299,CVE-2022-21426,CVE-2022-21434,CVE-2022-21443,CVE-2022-21449,CVE-2022-21476,CVE-2022-21496
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
openSUSE Leap 15.3 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Manager Server 4.1 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Manager Retail Branch Server 4.1 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Manager Proxy 4.1 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Server for SAP 15 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Server 15-LTSS (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Module for Legacy Software 15-SP4 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Module for Legacy Software 15-SP3 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Enterprise Storage 7 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Enterprise Storage 6 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE CaaS Platform 4.0 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 18 Swamp Workflow Management 2022-09-06 10:27:54 UTC
SUSE-SU-2022:3092-1: An update that fixes 9 vulnerabilities is now available.

Category: security (important)
Bug References: 1198671,1198672,1198673,1198674,1198675,1198935,1201684,1201692,1201694
CVE References: CVE-2021-41041,CVE-2022-21426,CVE-2022-21434,CVE-2022-21443,CVE-2022-21476,CVE-2022-21496,CVE-2022-21540,CVE-2022-21541,CVE-2022-34169
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    java-1_8_0-openj9-1.8.0.345-150200.3.24.1
openSUSE Leap 15.3 (src):    java-1_8_0-openj9-1.8.0.345-150200.3.24.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.