KLA12331
Multiple vulnerabilities in Oracle Java SE

Updated: 11/02/2021
Detect date
?
09/28/2021
Severity
?
Warning
Description

Multiple vulnerabilities were found in Oracle Java SE. Malicious users can exploit these vulnerabilities to bypass security restrictions, obtain sensitive information, cause denial of service, gain privileges, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. Security vulnerability in JSSE component can be exploited remotely to bypass security restrictions.
  2. Security vulnerability can be exploited remotely to bypass security restrictions.
  3. Vulnerability in JSSE component of Java SE can be exploited to cause denial of service.
  4. Vulnerability in Keytool component of Java SE can be exploited to obtain sensitive information;
  5. Security vulnerability in Hotspot component can be exploited remotely to bypass security restrictions.
  6. Vulnerability in Utility component of Java SE can be exploited to cause denial of service.
  7. Vulnerability in Swing component of Java SE can be exploited to cause denial of service.
  8. Vulnerability in JSSE component of Java SE can be exploited to obtain sensitive information;
  9. Vulnerability in ImageIO component of Java SE can be exploited to obtain sensitive information;
  10. Vulnerability in Libraries component of Java SE can be exploited to obtain sensitive information.
  11. A remote code execution vulnerability in Deployment component can be exploited remotely to execute arbitrary code.
Affected products

Java SE: 7u311, 8u301, 11.0.12, 17;

Solution

Update to the latest version
Download Java

Original advisories

Oracle Critical Patch Update Advisory – October 2021

Impacts
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]
Related products
Oracle Java JRE 1.7.x
Oracle Java JRE 1.8.x
CVE-IDS
?
CVE-2021-356030.0Unknown
CVE-2021-35170.0Unknown
CVE-2021-355780.0Unknown
CVE-2021-355640.0Unknown
CVE-2021-355880.0Unknown
CVE-2021-355610.0Unknown
CVE-2021-355590.0Unknown
CVE-2021-355500.0Unknown
CVE-2021-355860.0Unknown
CVE-2021-355560.0Unknown
CVE-2021-355670.0Unknown
CVE-2021-35220.0Unknown
CVE-2021-355650.0Unknown
CVE-2021-355600.0Unknown
Find out the statistics of the vulnerabilities spreading in your region