KLA12331
Multiple vulnerabilities in Oracle Java SE

Обновлено: 02/11/2021
Дата обнаружения
28/09/2021
Уровень угрозы
Warning
Описание

Multiple vulnerabilities were found in Oracle Java SE. Malicious users can exploit these vulnerabilities to bypass security restrictions, obtain sensitive information, cause denial of service, gain privileges, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. Security vulnerability in JSSE component can be exploited remotely to bypass security restrictions.
  2. Security vulnerability can be exploited remotely to bypass security restrictions.
  3. Vulnerability in JSSE component of Java SE can be exploited to cause denial of service.
  4. Vulnerability in Keytool component of Java SE can be exploited to obtain sensitive information;
  5. Security vulnerability in Hotspot component can be exploited remotely to bypass security restrictions.
  6. Vulnerability in Utility component of Java SE can be exploited to cause denial of service.
  7. Vulnerability in Swing component of Java SE can be exploited to cause denial of service.
  8. Vulnerability in JSSE component of Java SE can be exploited to obtain sensitive information;
  9. Vulnerability in ImageIO component of Java SE can be exploited to obtain sensitive information;
  10. Vulnerability in Libraries component of Java SE can be exploited to obtain sensitive information.
  11. A remote code execution vulnerability in Deployment component can be exploited remotely to execute arbitrary code.
Пораженные продукты

Java SE: 7u311, 8u301, 11.0.12, 17;

Решение

Update to the latest version
Download Java

Первичный источник обнаружения
Oracle Critical Patch Update Advisory - October 2021
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]
Связанные продукты
Oracle Java JRE 1.7.x
Oracle Java JRE 1.8.x
Узнай статистику распространения уязвимостей в твоем регионе