Bug 1213485 (CVE-2023-22043) - VUL-0: CVE-2023-22043: java-17-openjdk,java-11-openjdk,java-1_8_0-ibm,java-1_8_0-openjdk: Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u371
Summary: VUL-0: CVE-2023-22043: java-17-openjdk,java-11-openjdk,java-1_8_0-ibm,java-1_...
Status: RESOLVED INVALID
Alias: CVE-2023-22043
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Fridrich Strba
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/372911/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-22043:5.9:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-07-19 13:46 UTC by Thomas Leroy
Modified: 2023-08-20 09:50 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2023-07-19 13:46:50 UTC
CVE-2023-22043

Vulnerability in Oracle Java SE (component: JavaFX).   The supported version
that is affected is Oracle Java SE: 8u371. Difficult to exploit vulnerability
allows unauthenticated attacker with network access via multiple protocols to
compromise Oracle Java SE.  Successful attacks of this vulnerability can result
in  unauthorized creation, deletion or modification access to critical data or
all Oracle Java SE accessible data. Note: This vulnerability applies to Java
deployments, typically in clients running sandboxed Java Web Start applications
or sandboxed Java applets, that load and run untrusted code (e.g., code that
comes from the internet) and rely on the Java sandbox for security. This
vulnerability does not apply to Java deployments, typically in servers, that
load and run only trusted code (e.g., code installed by an administrator). CVSS
3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector:
(CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-22043
https://www.cve.org/CVERecord?id=CVE-2023-22043
https://www.oracle.com/security-alerts/cpujul2023.html
Comment 1 Thomas Leroy 2023-07-19 13:47:22 UTC
Fridrich, what are the packages shipping Java SE?