Bug 1204473 - (CVE-2022-21619) VUL-0: CVE-2022-21619: java-1_8_0-openjdk,java-17-openjdk,java-11-openjdk: unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE
(CVE-2022-21619)
VUL-0: CVE-2022-21619: java-1_8_0-openjdk,java-17-openjdk,java-11-openjdk: un...
Status: NEW
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Minor
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/345683/
CVSSv3.1:SUSE:CVE-2022-21619:3.7:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-10-19 08:52 UTC by Thomas Leroy
Modified: 2022-12-13 14:27 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2022-10-19 08:52:21 UTC
CVE-2022-21619

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product
of Oracle Java SE (component: Security). Supported versions that are affected
are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM
Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit
vulnerability allows unauthenticated attacker with network access via multiple
protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.
Successful attacks of this vulnerability can result in unauthorized update,
insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise
Edition accessible data. Note: This vulnerability applies to Java deployments,
typically in clients running sandboxed Java Web Start applications or sandboxed
Java applets, that load and run untrusted code (e.g., code that comes from the
internet) and rely on the Java sandbox for security. This vulnerability can also
be exploited by using APIs in the specified Component, e.g., through a web
service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Integrity
impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-21619
https://www.oracle.com/security-alerts/cpuoct2022.html
https://www.cve.org/CVERecord?id=CVE-2022-21619
Comment 5 Swamp Workflow Management 2022-11-18 20:33:13 UTC
SUSE-SU-2022:4078-1: An update that solves 6 vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 1203476,1204468,1204471,1204472,1204473,1204475,1204480,1204523
CVE References: CVE-2022-21618,CVE-2022-21619,CVE-2022-21624,CVE-2022-21626,CVE-2022-21628,CVE-2022-39399
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
openSUSE Leap 15.3 (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Manager Server 4.1 (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Manager Retail Branch Server 4.1 (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Manager Proxy 4.1 (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise Server for SAP 15 (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise Server 15-SP2-BCL (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise Server 15-SP1-BCL (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise Server 15-LTSS (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise Module for Basesystem 15-SP4 (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Enterprise Storage 7 (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE Enterprise Storage 6 (src):    java-11-openjdk-11.0.17.0-150000.3.86.2
SUSE CaaS Platform 4.0 (src):    java-11-openjdk-11.0.17.0-150000.3.86.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Swamp Workflow Management 2022-11-18 20:35:49 UTC
SUSE-SU-2022:4080-1: An update that solves 6 vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 1203476,1204468,1204471,1204472,1204473,1204475,1204480,1204523
CVE References: CVE-2022-21618,CVE-2022-21619,CVE-2022-21624,CVE-2022-21626,CVE-2022-21628,CVE-2022-39399
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP5 (src):    java-11-openjdk-11.0.17.0-3.49.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2022-11-18 20:37:04 UTC
SUSE-SU-2022:4079-1: An update that solves 5 vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1203476,1204468,1204472,1204473,1204475,1204480
CVE References: CVE-2022-21618,CVE-2022-21619,CVE-2022-21624,CVE-2022-21628,CVE-2022-39399
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    java-17-openjdk-17.0.5.0-150400.3.6.1
SUSE Linux Enterprise Module for Basesystem 15-SP4 (src):    java-17-openjdk-17.0.5.0-150400.3.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2022-11-22 14:27:01 UTC
SUSE-SU-2022:4166-1: An update that solves 10 vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1201684,1201685,1201692,1201694,1202427,1204468,1204471,1204472,1204473,1204475,1204480,1205302
CVE References: CVE-2022-21540,CVE-2022-21541,CVE-2022-21549,CVE-2022-21618,CVE-2022-21619,CVE-2022-21624,CVE-2022-21626,CVE-2022-21628,CVE-2022-34169,CVE-2022-39399
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1
openSUSE Leap 15.3 (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1
SUSE Manager Server 4.1 (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1
SUSE Manager Retail Branch Server 4.1 (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1
SUSE Manager Proxy 4.1 (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1
SUSE Linux Enterprise Server for SAP 15 (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1
SUSE Linux Enterprise Server 15-LTSS (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1
SUSE Linux Enterprise Module for Legacy Software 15-SP4 (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1
SUSE Linux Enterprise Module for Legacy Software 15-SP3 (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1
SUSE Enterprise Storage 7 (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1
SUSE Enterprise Storage 6 (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1
SUSE CaaS Platform 4.0 (src):    java-1_8_0-ibm-1.8.0_sr7.20-150000.3.65.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2022-11-28 14:35:29 UTC
SUSE-SU-2022:4250-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1204471,1204472,1204473,1204475,1204703
CVE References: CVE-2022-21619,CVE-2022-21624,CVE-2022-21626,CVE-2022-21628,CVE-2022-3676
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    java-1_8_0-openj9-1.8.0.352-150200.3.27.1
openSUSE Leap 15.3 (src):    java-1_8_0-openj9-1.8.0.352-150200.3.27.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Swamp Workflow Management 2022-11-29 20:39:27 UTC
SUSE-SU-2022:4290-1: An update that solves 6 vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1204468,1204471,1204472,1204473,1204475,1204480,1205302
CVE References: CVE-2022-21618,CVE-2022-21619,CVE-2022-21624,CVE-2022-21626,CVE-2022-21628,CVE-2022-39399
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    java-1_8_0-ibm-1.8.0_sr7.20-30.99.1
SUSE OpenStack Cloud 9 (src):    java-1_8_0-ibm-1.8.0_sr7.20-30.99.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    java-1_8_0-ibm-1.8.0_sr7.20-30.99.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    java-1_8_0-ibm-1.8.0_sr7.20-30.99.1
SUSE Linux Enterprise Server 12-SP5 (src):    java-1_8_0-ibm-1.8.0_sr7.20-30.99.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    java-1_8_0-ibm-1.8.0_sr7.20-30.99.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    java-1_8_0-ibm-1.8.0_sr7.20-30.99.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_8_0-ibm-1.8.0_sr7.20-30.99.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Swamp Workflow Management 2022-12-08 20:30:10 UTC
SUSE-SU-2022:4373-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1204471,1204472,1204473,1204475
CVE References: CVE-2022-21619,CVE-2022-21624,CVE-2022-21626,CVE-2022-21628
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    java-1_8_0-openjdk-1.8.0.352-27.81.1
SUSE OpenStack Cloud 9 (src):    java-1_8_0-openjdk-1.8.0.352-27.81.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    java-1_8_0-openjdk-1.8.0.352-27.81.1
SUSE Linux Enterprise Server 12-SP5 (src):    java-1_8_0-openjdk-1.8.0.352-27.81.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    java-1_8_0-openjdk-1.8.0.352-27.81.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    java-1_8_0-openjdk-1.8.0.352-27.81.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_8_0-openjdk-1.8.0.352-27.81.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Swamp Workflow Management 2022-12-13 14:27:11 UTC
SUSE-SU-2022:4452-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1204471,1204472,1204473,1204475
CVE References: CVE-2022-21619,CVE-2022-21624,CVE-2022-21626,CVE-2022-21628
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1
openSUSE Leap 15.3 (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1
SUSE Manager Server 4.1 (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1
SUSE Manager Retail Branch Server 4.1 (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1
SUSE Manager Proxy 4.1 (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1
SUSE Linux Enterprise Server for SAP 15 (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1
SUSE Linux Enterprise Server 15-LTSS (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1
SUSE Linux Enterprise Module for Legacy Software 15-SP4 (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1
SUSE Linux Enterprise Module for Legacy Software 15-SP3 (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1
SUSE Enterprise Storage 7 (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1
SUSE Enterprise Storage 6 (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1
SUSE CaaS Platform 4.0 (src):    java-1_8_0-openjdk-1.8.0.352-150000.3.73.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.