Wind River Support Network

HomeDefectsLIN1021-6730
Not to be fixed

LIN1021-6730 : Security Advisory - openjdk-11 - CVE-2023-22091

Created: Oct 17, 2023    Updated: Nov 29, 2023
Resolved Date: Oct 19, 2023
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler).  Supported versions that are affected are Oracle GraalVM for JDK: 17.0.8 and  20.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM for JDK.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle GraalVM for JDK accessible data as well as  unauthorized read access to a subset of Oracle GraalVM for JDK accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).

CREATE(Triage):(User=admin) CVE-2023-22091 (https://nvd.nist.gov/vuln/detail/CVE-2023-22091)
Live chat
Online