Wind River Support Network

HomeDefectsLIN1021-6728
Not to be fixed

LIN1021-6728 : Security Advisory - openjdk-11 - CVE-2023-22067

Created: Oct 17, 2023    Updated: Nov 29, 2023
Resolved Date: Oct 19, 2023
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

Vulnerability in Oracle Java SE (component: CORBA).  Supported versions that are affected are Oracle Java SE: 8u381 and  8u381-perf. Easily exploitable vulnerability allows unauthenticated attacker with network access via CORBA to compromise Oracle Java SE.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).


CREATE(Triage):(User=admin) CVE-2023-22067 (https://nvd.nist.gov/vuln/detail/CVE-2023-22067)
Live chat
Online