Bug 1198672 (CVE-2022-21426)

Summary: VUL-0: CVE-2022-21426: java-1_7_0-openjdk,java-1_8_0-openjdk,java-11-openjdk,java-17-openjdk: unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE
Product: [Novell Products] SUSE Security Incidents Reporter: Alexander Bergmann <abergmann>
Component: IncidentsAssignee: Fridrich Strba <fstrba>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: fstrba, gabriele.sonnu, rfrohl, smash_bz, stoyan.manolov
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/329538/
Whiteboard: CVSSv3.1:SUSE:CVE-2022-21426:5.3:(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Alexander Bergmann 2022-04-20 07:16:41 UTC
CVE-2022-21426

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product
of Oracle Java SE (component: JAXP). Supported versions that are affected are
Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise
Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows
unauthenticated attacker with network access via multiple protocols to
compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks
of this vulnerability can result in unauthorized ability to cause a partial
denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise
Edition. Note: This vulnerability applies to Java deployments, typically in
clients running sandboxed Java Web Start applications or sandboxed Java applets,
that load and run untrusted code (e.g., code that comes from the internet) and
rely on the Java sandbox for security. This vulnerability can also be exploited
by using APIs in the specified Component, e.g., through a web service which
supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS
Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-21426
https://www.oracle.com/security-alerts/cpuapr2022.html#CVE-2022-21426
https://www.oracle.com/security-alerts/cpuapr2022.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21426
Comment 2 Swamp Workflow Management 2022-04-29 19:20:58 UTC
SUSE-SU-2022:1474-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1198671,1198672,1198673,1198674,1198675
CVE References: CVE-2022-21426,CVE-2022-21434,CVE-2022-21443,CVE-2022-21476,CVE-2022-21496
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP5 (src):    java-11-openjdk-11.0.15.0-3.43.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 3 Swamp Workflow Management 2022-05-03 19:21:24 UTC
SUSE-SU-2022:1513-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1198671,1198672,1198673,1198674,1198675
CVE References: CVE-2022-21426,CVE-2022-21434,CVE-2022-21443,CVE-2022-21476,CVE-2022-21496
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
openSUSE Leap 15.3 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Manager Server 4.1 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Manager Retail Branch Server 4.1 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Manager Proxy 4.1 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Server for SAP 15 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Server 15-SP2-BCL (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Server 15-LTSS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Realtime Extension 15-SP2 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Module for Basesystem 15-SP4 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Enterprise Storage 7 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE Enterprise Storage 6 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1
SUSE CaaS Platform 4.0 (src):    java-11-openjdk-11.0.15.0-150000.3.80.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2022-07-22 19:19:26 UTC
SUSE-SU-2022:2531-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1198671,1198672,1198673,1198674,1198675
CVE References: CVE-2022-21426,CVE-2022-21434,CVE-2022-21443,CVE-2022-21476,CVE-2022-21496
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    java-1_8_0-openjdk-1.8.0.332-27.75.2
SUSE OpenStack Cloud 9 (src):    java-1_8_0-openjdk-1.8.0.332-27.75.2
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    java-1_8_0-openjdk-1.8.0.332-27.75.2
SUSE Linux Enterprise Server 12-SP5 (src):    java-1_8_0-openjdk-1.8.0.332-27.75.2
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    java-1_8_0-openjdk-1.8.0.332-27.75.2
SUSE Linux Enterprise Server 12-SP3-BCL (src):    java-1_8_0-openjdk-1.8.0.332-27.75.2
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_8_0-openjdk-1.8.0.332-27.75.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2022-07-22 19:21:00 UTC
SUSE-SU-2022:2530-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1198671,1198672,1198673,1198674,1198675
CVE References: CVE-2022-21426,CVE-2022-21434,CVE-2022-21443,CVE-2022-21476,CVE-2022-21496
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
openSUSE Leap 15.3 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Manager Server 4.1 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Manager Retail Branch Server 4.1 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Manager Proxy 4.1 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Server for SAP 15 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Server 15-LTSS (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Module for Legacy Software 15-SP4 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Linux Enterprise Module for Legacy Software 15-SP3 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Enterprise Storage 7 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE Enterprise Storage 6 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1
SUSE CaaS Platform 4.0 (src):    java-1_8_0-openjdk-1.8.0.332-150000.3.67.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Swamp Workflow Management 2022-07-23 16:16:06 UTC
SUSE-SU-2022:2539-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1191912,1194931,1198670,1198671,1198672,1198673,1198674,1198675,1201643
CVE References: CVE-2021-35561,CVE-2022-21299,CVE-2022-21426,CVE-2022-21434,CVE-2022-21443,CVE-2022-21449,CVE-2022-21476,CVE-2022-21496
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    java-1_7_1-ibm-1.7.1_sr5.10-38.71.1
SUSE OpenStack Cloud 9 (src):    java-1_7_1-ibm-1.7.1_sr5.10-38.71.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    java-1_7_1-ibm-1.7.1_sr5.10-38.71.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    java-1_7_1-ibm-1.7.1_sr5.10-38.71.1
SUSE Linux Enterprise Server 12-SP5 (src):    java-1_7_1-ibm-1.7.1_sr5.10-38.71.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    java-1_7_1-ibm-1.7.1_sr5.10-38.71.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    java-1_7_1-ibm-1.7.1_sr5.10-38.71.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_7_1-ibm-1.7.1_sr5.10-38.71.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 11 Swamp Workflow Management 2022-07-23 16:17:36 UTC
SUSE-SU-2022:2540-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1191912,1194931,1198670,1198671,1198672,1198673,1198674,1198675,1201643
CVE References: CVE-2021-35561,CVE-2022-21299,CVE-2022-21426,CVE-2022-21434,CVE-2022-21443,CVE-2022-21449,CVE-2022-21476,CVE-2022-21496
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    java-1_8_0-ibm-1.8.0_sr7.10-30.90.1
SUSE OpenStack Cloud 9 (src):    java-1_8_0-ibm-1.8.0_sr7.10-30.90.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    java-1_8_0-ibm-1.8.0_sr7.10-30.90.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    java-1_8_0-ibm-1.8.0_sr7.10-30.90.1
SUSE Linux Enterprise Server 12-SP5 (src):    java-1_8_0-ibm-1.8.0_sr7.10-30.90.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    java-1_8_0-ibm-1.8.0_sr7.10-30.90.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    java-1_8_0-ibm-1.8.0_sr7.10-30.90.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_8_0-ibm-1.8.0_sr7.10-30.90.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Swamp Workflow Management 2022-08-03 16:24:04 UTC
SUSE-SU-2022:2650-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1191912,1194931,1198670,1198671,1198672,1198673,1198674,1198675,1201643
CVE References: CVE-2021-35561,CVE-2022-21299,CVE-2022-21426,CVE-2022-21434,CVE-2022-21443,CVE-2022-21449,CVE-2022-21476,CVE-2022-21496
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
openSUSE Leap 15.3 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Manager Server 4.1 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Manager Retail Branch Server 4.1 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Manager Proxy 4.1 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Server for SAP 15 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Server 15-LTSS (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Module for Legacy Software 15-SP4 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Linux Enterprise Module for Legacy Software 15-SP3 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Enterprise Storage 7 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE Enterprise Storage 6 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1
SUSE CaaS Platform 4.0 (src):    java-1_8_0-ibm-1.8.0_sr7.10-150000.3.59.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 15 Swamp Workflow Management 2022-09-06 10:27:59 UTC
SUSE-SU-2022:3092-1: An update that fixes 9 vulnerabilities is now available.

Category: security (important)
Bug References: 1198671,1198672,1198673,1198674,1198675,1198935,1201684,1201692,1201694
CVE References: CVE-2021-41041,CVE-2022-21426,CVE-2022-21434,CVE-2022-21443,CVE-2022-21476,CVE-2022-21496,CVE-2022-21540,CVE-2022-21541,CVE-2022-34169
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    java-1_8_0-openj9-1.8.0.345-150200.3.24.1
openSUSE Leap 15.3 (src):    java-1_8_0-openj9-1.8.0.345-150200.3.24.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.