KLA12588
Multiple vulnerabilities in Oracle Java SE and GraalVM

Обновлено: 28/09/2023
Дата обнаружения
19/07/2022
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Oracle Java SE and GraalVM. Malicious users can exploit these vulnerabilities to obtain sensitive information, execute arbitrary code, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. Information disclosure vulnerability can be exploited to obtain sensitive information.
  2. RCE vulnerability in Java XSLTcan be exploited to cause denial of service or execute arbitrary code.
  3. Security vulnerability can be exploited to bypass security restrictions.
Эксплуатация

Public exploits exist for this vulnerability.

Пораженные продукты

Oracle GraalVM Enterprise Edition 20.3.6, 21.3.2, 22.1.0

Oracle Java SE 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1

Решение

Update to the latest version
Download Java

Первичный источник обнаружения
Oracle Critical Patch Update Advisory - July 2022
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

SB 
[?]

PE 
[?]
Связанные продукты
Oracle Java JRE 1.7.x
Oracle Java JRE 1.8.x
CVE-IDS
CVE-2022-215405.0Warning
CVE-2022-341695.0Warning
CVE-2022-215495.0Warning
CVE-2022-215415.0Warning
Узнай статистику распространения уязвимостей в твоем регионе