PT-2022-6859 · Oracle+9 · Java Se+11

Published

2022-10-18

·

Updated

2026-05-08

·

CVE-2022-21618

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 17.0.4.1 through 19 Oracle GraalVM Enterprise Edition versions 21.3.3 through 22.2.0
Description The issue is related to a vulnerability in the JGSS component of Oracle Java SE and Oracle GraalVM Enterprise Edition, allowing an unauthenticated attacker with network access via Kerberos to compromise the system. This can result in unauthorized update, insert, or delete access to some accessible data. The vulnerability applies to Java deployments that load and run untrusted code and rely on the Java sandbox for security. It can also be exploited through APIs in the specified component.
Recommendations For Oracle Java SE versions 17.0.4.1 through 19, update to a version that contains a fix for this issue. For Oracle GraalVM Enterprise Edition versions 21.3.3 through 22.2.0, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the JGSS component until a patch is available. Avoid using APIs in the specified component that supply data to untrusted sources until the issue is resolved.

Exploit

Fix

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2022:6999
ALSA-2022:7000
ALSA-2022:7012
ALSA-2022:7013
ALT-PU-2022-7669
ALT-PU-2022-7672
ALT-PU-2023-8449
ALT-PU-2023-8454
ALT-PU-2023-8460
BDU:2023-05188
BIT-JAVA-2022-21618
BIT-JAVA-MIN-2022-21618
BIT-JRE-2022-21618
CESA-2022_7000
CESA-2022_7008
CESA-2022_7012
CVE-2022-21618
DSA-5335-1
MGASA-2022-0435
OESA-2022-2150
OESA-2022-2151
OESA-2022-2152
OESA-2023-1011
OPENSUSE-SU-2022_4078-1
OPENSUSE-SU-2022_4079-1
OPENSUSE-SU-2022_4166-1
OPENSUSE-SU-2024:12431-1
OPENSUSE-SU-2024:12432-1
OPENSUSE-SU-2024:12441-1
OPENSUSE-SU-2024:12442-1
OPENSUSE-SU-2024:12463-1
OPENSUSE-SU-2024:12464-1
OPENSUSE-SU-2024:12526-1
OPENSUSE-SU-2025:0066-1
OPENSUSE-SU-2025:0067-1
RHSA-2022:6999
RHSA-2022:7000
RHSA-2022:7001
RHSA-2022:7008
RHSA-2022:7009
RHSA-2022:7010
RHSA-2022:7011
RHSA-2022:7012
RHSA-2022:7013
RHSA-2022_6999
RHSA-2022_7000
RHSA-2022_7008
RHSA-2022_7012
RHSA-2022_7013
RLSA-2022:6999
RLSA-2022:7000
RLSA-2022:7012
RLSA-2022:7013
ROSA-SA-2023-2151
SUSE-SU-2022:4078-1
SUSE-SU-2022:4079-1
SUSE-SU-2022:4080-1
SUSE-SU-2022:4166-1
SUSE-SU-2022:4290-1
SUSE-SU-2022_4078-1
SUSE-SU-2022_4079-1
SUSE-SU-2022_4080-1
SUSE-SU-2022_4290-1
USN-5719-1

Affected Products

Alt Linux
Almalinux
Centos
Graalvm Enterprise Edition
Java Platform
Java Se
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu