PT-2023-1249 · Oracle+10 · Java Se+12

Juraj Somorovsky

+3

·

Published

2023-01-17

·

Updated

2026-05-08

·

CVE-2023-21835

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 11.0.17, 17.0.5, 19.0.1 Oracle GraalVM Enterprise Edition versions 20.3.8, 21.3.4, 22.3.0
Description The issue is related to an easily exploitable vulnerability in the JSSE component of Oracle Java SE and Oracle GraalVM Enterprise Edition. This vulnerability allows an unauthenticated attacker with network access via DTLS to compromise the system, resulting in a partial denial of service. The vulnerability applies to Java deployments that load and run untrusted code, such as sandboxed Java Web Start applications or sandboxed Java applets, and rely on the Java sandbox for security.
Recommendations For Oracle Java SE versions 11.0.17, 17.0.5, 19.0.1, update to a newer version that contains a fix for this issue. For Oracle GraalVM Enterprise Edition versions 20.3.8, 21.3.4, 22.3.0, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the DTLS protocol to minimize the risk of exploitation. Note: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALSA-2023:0192
ALSA-2023:0194
ALSA-2023:0200
ALSA-2023:0202
ALT-PU-2023-8449
ALT-PU-2023-8450
ALT-PU-2023-8453
ALT-PU-2023-8454
ALT-PU-2023-8455
ALT-PU-2023-8460
BDU:2023-00510
BIT-JAVA-2023-21835
BIT-JAVA-MIN-2023-21835
BIT-JRE-2023-21835
CESA-2023_0192
CESA-2023_0195
CESA-2023_0200
CVE-2023-21835
DLA-3307-1
DSA-5331-1
DSA-5335-1
MGASA-2023-0037
OESA-2023-1600
OESA-2023-1601
OESA-2023-1602
OESA-2023-1603
OESA-2023-1617
OESA-2023-1618
OESA-2023-1650
OESA-2023-1737
OESA-2023-1738
OESA-2023-1739
OPENSUSE-SU-2023_0435-1
OPENSUSE-SU-2024:12661-1
OPENSUSE-SU-2024:12663-1
OPENSUSE-SU-2024:12669-1
OPENSUSE-SU-2024:12719-1
OPENSUSE-SU-2024:12720-1
OPENSUSE-SU-2024:12754-1
OPENSUSE-SU-2024:12755-1
OPENSUSE-SU-2025:0066-1
OPENSUSE-SU-2025:0067-1
RHSA-2023:0190
RHSA-2023:0191
RHSA-2023:0192
RHSA-2023:0193
RHSA-2023:0194
RHSA-2023:0195
RHSA-2023:0196
RHSA-2023:0197
RHSA-2023:0198
RHSA-2023:0199
RHSA-2023:0200
RHSA-2023:0201
RHSA-2023:0202
RHSA-2023_0192
RHSA-2023_0194
RHSA-2023_0195
RHSA-2023_0200
RHSA-2023_0202
RLSA-2023:0192
RLSA-2023:0194
RLSA-2023:0200
RLSA-2023:0202
ROSA-SA-2023-2138
SUSE-SU-2023:0435-1
SUSE-SU-2023:0436-1
SUSE-SU-2023:0752-1
SUSE-SU-2023:1823-1
SUSE-SU-2023:1850-1
SUSE-SU-2023_0435-1
SUSE-SU-2023_0436-1
SUSE-SU-2023_0752-1
USN-5897-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Graalvm Enterprise Edition
Java Platform
Java Se
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu