Bugzilla – Bug 1191904
VUL-0: CVE-2021-35578: java-11-openjdk,java-1_7_0-openjdk,java-1_8_0-openjdk: Unexpected exception raised during TLS handshake (JSSE, 8267729)
Last modified: 2022-04-08 13:18:20 UTC
CVE-2021-35578 Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). References: https://bugzilla.redhat.com/show_bug.cgi?id=2015653 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-35578 https://www.oracle.com/security-alerts/cpuoct2021.html#CVE-2021-35578 https://www.oracle.com/security-alerts/cpuoct2021.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35578
SUSE-SU-2021:3528-1: An update that fixes 10 vulnerabilities is now available. Category: security (important) Bug References: 1191901,1191903,1191904,1191906,1191909,1191910,1191911,1191912,1191913,1191914 CVE References: CVE-2021-35550,CVE-2021-35556,CVE-2021-35559,CVE-2021-35561,CVE-2021-35564,CVE-2021-35565,CVE-2021-35567,CVE-2021-35578,CVE-2021-35586,CVE-2021-35603 JIRA References: Sources used: SUSE Linux Enterprise Server 12-SP5 (src): java-11-openjdk-11.0.13.0-3.33.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:3615-1: An update that fixes 15 vulnerabilities is now available. Category: security (important) Bug References: 1185055,1185056,1188564,1188565,1188566,1191901,1191903,1191904,1191906,1191909,1191910,1191911,1191912,1191913,1191914 CVE References: CVE-2021-2161,CVE-2021-2163,CVE-2021-2341,CVE-2021-2369,CVE-2021-2388,CVE-2021-35550,CVE-2021-35556,CVE-2021-35559,CVE-2021-35561,CVE-2021-35564,CVE-2021-35565,CVE-2021-35567,CVE-2021-35578,CVE-2021-35586,CVE-2021-35603 JIRA References: Sources used: openSUSE Leap 15.3 (src): java-1_8_0-openj9-1.8.0.312-3.18.2
openSUSE-SU-2021:1455-1: An update that fixes 15 vulnerabilities is now available. Category: security (important) Bug References: 1185055,1185056,1188564,1188565,1188566,1191901,1191903,1191904,1191906,1191909,1191910,1191911,1191912,1191913,1191914 CVE References: CVE-2021-2161,CVE-2021-2163,CVE-2021-2341,CVE-2021-2369,CVE-2021-2388,CVE-2021-35550,CVE-2021-35556,CVE-2021-35559,CVE-2021-35561,CVE-2021-35564,CVE-2021-35565,CVE-2021-35567,CVE-2021-35578,CVE-2021-35586,CVE-2021-35603 JIRA References: Sources used: openSUSE Leap 15.2 (src): java-1_8_0-openj9-1.8.0.312-lp152.3.12.1
SUSE-SU-2021:3671-1: An update that fixes 10 vulnerabilities is now available. Category: security (important) Bug References: 1191901,1191903,1191904,1191906,1191909,1191910,1191911,1191912,1191913,1191914 CVE References: CVE-2021-35550,CVE-2021-35556,CVE-2021-35559,CVE-2021-35561,CVE-2021-35564,CVE-2021-35565,CVE-2021-35567,CVE-2021-35578,CVE-2021-35586,CVE-2021-35603 JIRA References: Sources used: SUSE Linux Enterprise Server for SAP 15-SP1 (src): java-11-openjdk-11.0.13.0-3.65.1 SUSE Linux Enterprise Server for SAP 15 (src): java-11-openjdk-11.0.13.0-3.65.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): java-11-openjdk-11.0.13.0-3.65.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): java-11-openjdk-11.0.13.0-3.65.1 SUSE Linux Enterprise Server 15-LTSS (src): java-11-openjdk-11.0.13.0-3.65.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src): java-11-openjdk-11.0.13.0-3.65.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2 (src): java-11-openjdk-11.0.13.0-3.65.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): java-11-openjdk-11.0.13.0-3.65.1 SUSE Linux Enterprise Module for Basesystem 15-SP2 (src): java-11-openjdk-11.0.13.0-3.65.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): java-11-openjdk-11.0.13.0-3.65.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): java-11-openjdk-11.0.13.0-3.65.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): java-11-openjdk-11.0.13.0-3.65.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): java-11-openjdk-11.0.13.0-3.65.1 SUSE Enterprise Storage 6 (src): java-11-openjdk-11.0.13.0-3.65.1 SUSE CaaS Platform 4.0 (src): java-11-openjdk-11.0.13.0-3.65.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:3671-1: An update that fixes 10 vulnerabilities is now available. Category: security (important) Bug References: 1191901,1191903,1191904,1191906,1191909,1191910,1191911,1191912,1191913,1191914 CVE References: CVE-2021-35550,CVE-2021-35556,CVE-2021-35559,CVE-2021-35561,CVE-2021-35564,CVE-2021-35565,CVE-2021-35567,CVE-2021-35578,CVE-2021-35586,CVE-2021-35603 JIRA References: Sources used: openSUSE Leap 15.3 (src): java-11-openjdk-11.0.13.0-3.65.1
openSUSE-SU-2021:1480-1: An update that fixes 10 vulnerabilities is now available. Category: security (important) Bug References: 1191901,1191903,1191904,1191906,1191909,1191910,1191911,1191912,1191913,1191914 CVE References: CVE-2021-35550,CVE-2021-35556,CVE-2021-35559,CVE-2021-35561,CVE-2021-35564,CVE-2021-35565,CVE-2021-35567,CVE-2021-35578,CVE-2021-35586,CVE-2021-35603 JIRA References: Sources used: openSUSE Leap 15.2 (src): java-11-openjdk-11.0.13.0-lp152.2.21.2
openSUSE-SU-2021:3770-1: An update that fixes 11 vulnerabilities is now available. Category: security (important) Bug References: 1191901,1191903,1191904,1191905,1191906,1191909,1191910,1191911,1191912,1191913,1191914 CVE References: CVE-2021-35550,CVE-2021-35556,CVE-2021-35559,CVE-2021-35561,CVE-2021-35564,CVE-2021-35565,CVE-2021-35567,CVE-2021-35578,CVE-2021-35586,CVE-2021-35588,CVE-2021-35603 JIRA References: Sources used: openSUSE Leap 15.3 (src): java-1_8_0-openjdk-1.8.0.312-3.58.2
SUSE-SU-2021:3770-1: An update that fixes 11 vulnerabilities is now available. Category: security (important) Bug References: 1191901,1191903,1191904,1191905,1191906,1191909,1191910,1191911,1191912,1191913,1191914 CVE References: CVE-2021-35550,CVE-2021-35556,CVE-2021-35559,CVE-2021-35561,CVE-2021-35564,CVE-2021-35565,CVE-2021-35567,CVE-2021-35578,CVE-2021-35586,CVE-2021-35588,CVE-2021-35603 JIRA References: Sources used: SUSE Linux Enterprise Server for SAP 15-SP1 (src): java-1_8_0-openjdk-1.8.0.312-3.58.2 SUSE Linux Enterprise Server for SAP 15 (src): java-1_8_0-openjdk-1.8.0.312-3.58.2 SUSE Linux Enterprise Server 15-SP1-LTSS (src): java-1_8_0-openjdk-1.8.0.312-3.58.2 SUSE Linux Enterprise Server 15-SP1-BCL (src): java-1_8_0-openjdk-1.8.0.312-3.58.2 SUSE Linux Enterprise Server 15-LTSS (src): java-1_8_0-openjdk-1.8.0.312-3.58.2 SUSE Linux Enterprise Module for Legacy Software 15-SP3 (src): java-1_8_0-openjdk-1.8.0.312-3.58.2 SUSE Linux Enterprise Module for Legacy Software 15-SP2 (src): java-1_8_0-openjdk-1.8.0.312-3.58.2 SUSE Enterprise Storage 6 (src): java-1_8_0-openjdk-1.8.0.312-3.58.2 SUSE CaaS Platform 4.0 (src): java-1_8_0-openjdk-1.8.0.312-3.58.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2021:3771-1: An update that fixes 11 vulnerabilities is now available. Category: security (important) Bug References: 1191901,1191903,1191904,1191905,1191906,1191909,1191910,1191911,1191912,1191913,1191914 CVE References: CVE-2021-35550,CVE-2021-35556,CVE-2021-35559,CVE-2021-35561,CVE-2021-35564,CVE-2021-35565,CVE-2021-35567,CVE-2021-35578,CVE-2021-35586,CVE-2021-35588,CVE-2021-35603 JIRA References: Sources used: SUSE OpenStack Cloud Crowbar 9 (src): java-1_8_0-openjdk-1.8.0.312-27.66.1 SUSE OpenStack Cloud Crowbar 8 (src): java-1_8_0-openjdk-1.8.0.312-27.66.1 SUSE OpenStack Cloud 9 (src): java-1_8_0-openjdk-1.8.0.312-27.66.1 SUSE OpenStack Cloud 8 (src): java-1_8_0-openjdk-1.8.0.312-27.66.1 SUSE Linux Enterprise Server for SAP 12-SP4 (src): java-1_8_0-openjdk-1.8.0.312-27.66.1 SUSE Linux Enterprise Server for SAP 12-SP3 (src): java-1_8_0-openjdk-1.8.0.312-27.66.1 SUSE Linux Enterprise Server 12-SP5 (src): java-1_8_0-openjdk-1.8.0.312-27.66.1 SUSE Linux Enterprise Server 12-SP4-LTSS (src): java-1_8_0-openjdk-1.8.0.312-27.66.1 SUSE Linux Enterprise Server 12-SP3-LTSS (src): java-1_8_0-openjdk-1.8.0.312-27.66.1 SUSE Linux Enterprise Server 12-SP3-BCL (src): java-1_8_0-openjdk-1.8.0.312-27.66.1 SUSE Linux Enterprise Server 12-SP2-BCL (src): java-1_8_0-openjdk-1.8.0.312-27.66.1 HPE Helion Openstack 8 (src): java-1_8_0-openjdk-1.8.0.312-27.66.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:1500-1: An update that fixes 11 vulnerabilities is now available. Category: security (important) Bug References: 1191901,1191903,1191904,1191905,1191906,1191909,1191910,1191911,1191912,1191913,1191914 CVE References: CVE-2021-35550,CVE-2021-35556,CVE-2021-35559,CVE-2021-35561,CVE-2021-35564,CVE-2021-35565,CVE-2021-35567,CVE-2021-35578,CVE-2021-35586,CVE-2021-35588,CVE-2021-35603 JIRA References: Sources used: openSUSE Leap 15.2 (src): java-1_8_0-openjdk-1.8.0.312-lp152.2.18.2
SUSE-SU-2022:0107-1: An update that solves 12 vulnerabilities and has two fixes is now available. Category: security (important) Bug References: 1185055,1188564,1188565,1191902,1191904,1191905,1191909,1191910,1191911,1191913,1191914,1192052,1194198,1194232 CVE References: CVE-2021-2163,CVE-2021-2341,CVE-2021-2369,CVE-2021-35556,CVE-2021-35559,CVE-2021-35560,CVE-2021-35564,CVE-2021-35565,CVE-2021-35578,CVE-2021-35586,CVE-2021-35588,CVE-2021-41035 JIRA References: Sources used: SUSE OpenStack Cloud Crowbar 9 (src): java-1_8_0-ibm-1.8.0_sr7.0-30.84.1 SUSE OpenStack Cloud Crowbar 8 (src): java-1_8_0-ibm-1.8.0_sr7.0-30.84.1 SUSE OpenStack Cloud 9 (src): java-1_8_0-ibm-1.8.0_sr7.0-30.84.1 SUSE OpenStack Cloud 8 (src): java-1_8_0-ibm-1.8.0_sr7.0-30.84.1 SUSE Linux Enterprise Software Development Kit 12-SP5 (src): java-1_8_0-ibm-1.8.0_sr7.0-30.84.1 SUSE Linux Enterprise Server for SAP 12-SP4 (src): java-1_8_0-ibm-1.8.0_sr7.0-30.84.1 SUSE Linux Enterprise Server for SAP 12-SP3 (src): java-1_8_0-ibm-1.8.0_sr7.0-30.84.1 SUSE Linux Enterprise Server 12-SP5 (src): java-1_8_0-ibm-1.8.0_sr7.0-30.84.1 SUSE Linux Enterprise Server 12-SP4-LTSS (src): java-1_8_0-ibm-1.8.0_sr7.0-30.84.1 SUSE Linux Enterprise Server 12-SP3-LTSS (src): java-1_8_0-ibm-1.8.0_sr7.0-30.84.1 SUSE Linux Enterprise Server 12-SP3-BCL (src): java-1_8_0-ibm-1.8.0_sr7.0-30.84.1 SUSE Linux Enterprise Server 12-SP2-BCL (src): java-1_8_0-ibm-1.8.0_sr7.0-30.84.1 HPE Helion Openstack 8 (src): java-1_8_0-ibm-1.8.0_sr7.0-30.84.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2022:0108-1: An update that solves 12 vulnerabilities and has two fixes is now available. Category: security (important) Bug References: 1185055,1188564,1188565,1191902,1191904,1191905,1191909,1191910,1191911,1191913,1191914,1192052,1194198,1194232 CVE References: CVE-2021-2163,CVE-2021-2341,CVE-2021-2369,CVE-2021-35556,CVE-2021-35559,CVE-2021-35560,CVE-2021-35564,CVE-2021-35565,CVE-2021-35578,CVE-2021-35586,CVE-2021-35588,CVE-2021-41035 JIRA References: Sources used: openSUSE Leap 15.3 (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1
SUSE-SU-2022:0108-1: An update that solves 12 vulnerabilities and has two fixes is now available. Category: security (important) Bug References: 1185055,1188564,1188565,1191902,1191904,1191905,1191909,1191910,1191911,1191913,1191914,1192052,1194198,1194232 CVE References: CVE-2021-2163,CVE-2021-2341,CVE-2021-2369,CVE-2021-35556,CVE-2021-35559,CVE-2021-35560,CVE-2021-35564,CVE-2021-35565,CVE-2021-35578,CVE-2021-35586,CVE-2021-35588,CVE-2021-41035 JIRA References: Sources used: SUSE Manager Server 4.1 (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1 SUSE Manager Retail Branch Server 4.1 (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1 SUSE Manager Proxy 4.1 (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1 SUSE Linux Enterprise Server for SAP 15-SP2 (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1 SUSE Linux Enterprise Server for SAP 15-SP1 (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1 SUSE Linux Enterprise Server for SAP 15 (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1 SUSE Linux Enterprise Server 15-SP2-LTSS (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1 SUSE Linux Enterprise Server 15-LTSS (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1 SUSE Linux Enterprise Module for Legacy Software 15-SP3 (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1 SUSE Enterprise Storage 7 (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1 SUSE Enterprise Storage 6 (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1 SUSE CaaS Platform 4.5 (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1 SUSE CaaS Platform 4.0 (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
fixed
openSUSE-SU-2022:0108-1: An update that solves 12 vulnerabilities and has three fixes is now available. Category: security (important) Bug References: 1185055,1188564,1188565,1191902,1191904,1191905,1191909,1191910,1191911,1191913,1191914,1192052,1194198,1194232,1197518 CVE References: CVE-2021-2163,CVE-2021-2341,CVE-2021-2369,CVE-2021-35556,CVE-2021-35559,CVE-2021-35560,CVE-2021-35564,CVE-2021-35565,CVE-2021-35578,CVE-2021-35586,CVE-2021-35588,CVE-2021-41035 JIRA References: Sources used: openSUSE Leap 15.3 (src): java-1_8_0-ibm-1.8.0_sr7.0-3.53.1, seamonkey-2.53.11.1-lp153.17.5.1