PT-2023-2657 · Oracle+11 · Oracle Java Se+13

Beichendream

+1

·

Published

2022-10-19

·

Updated

2026-05-08

·

CVE-2023-21939

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 8u361, 8u361-perf, 11.0.18, 17.0.6, 20 Oracle GraalVM Enterprise Edition versions 20.3.9, 21.3.5, 22.3.1
Description The issue exists due to insufficient input validation in the Swing component of Oracle Java SE and Oracle GraalVM Enterprise Edition. This allows an unauthenticated attacker with network access via HTTP to compromise the system, resulting in unauthorized update, insert, or delete access to some accessible data. The vulnerability applies to Java deployments that load and run untrusted code and rely on the Java sandbox for security. It can also be exploited through APIs in the specified component, such as through a web service that supplies data to the APIs.
Recommendations For Oracle Java SE versions 8u361, 8u361-perf, 11.0.18, 17.0.6, 20, and Oracle GraalVM Enterprise Edition versions 20.3.9, 21.3.5, 22.3.1, consider disabling the Swing component until a patch is available. Restrict access to the vulnerable APIs in the specified component to minimize the risk of exploitation. Avoid using the affected Oracle Java SE and Oracle GraalVM Enterprise Edition versions in environments where untrusted code is executed. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022_6999
ALSA-2022_7000
ALSA-2022_7006
ALSA-2022_7007
ALSA-2022_7012
ALSA-2022_7013
ALSA-2023:1879
ALSA-2023:1880
ALSA-2023:1895
ALSA-2023:1898
ALSA-2023:1908
ALSA-2023:1909
ALSA-2023_0192
ALSA-2023_0194
ALSA-2023_0200
ALSA-2023_0202
ALSA-2023_0208
ALSA-2023_0210
ALSA-2023_1879
ALSA-2023_1880
ALSA-2023_1895
ALSA-2023_1898
ALSA-2023_1908
ALSA-2023_1909
ALSA-2023_4158
ALSA-2023_4159
ALSA-2023_4175
ALSA-2023_4176
ALSA-2023_4177
ALSA-2023_4178
ALSA-2023_5731
ALSA-2023_5733
ALSA-2023_5742
ALSA-2023_5744
ALSA-2023_5751
ALSA-2023_5753
ALSA-2023_6738
ALSA-2023_6887
ALSA-2024_0248
ALSA-2024_0249
ALSA-2024_0265
ALSA-2024_0266
ALSA-2024_0267
ALSA-2024_1818
ALSA-2024_1822
ALSA-2024_1825
ALSA-2024_1828
ALSA-2024_4563
ALSA-2024_4567
ALSA-2024_4568
ALSA-2024_4573
ALSA-2024_8117
ALSA-2024_8121
ALSA-2024_8124
ALSA-2024_8127
ALSA-2025_3845
ALSA-2025_3852
ALSA-2025_3855
ALT-PU-2022-7673
ALT-PU-2022-7674
ALT-PU-2023-8449
ALT-PU-2023-8454
ALT-PU-2023-8455
ALT-PU-2023-8460
ALT-PU-2023-8464
ALT-PU-2023-8465
ALT-PU-2023-8466
ALT-PU-2023-8467
ALT-PU-2023-8468
ALT-PU-2023-8469
ALT-PU-2023-8470
ALT-PU-2023-8471
ALT-PU-2023-8477
ALT-PU-2023-8482
ALT-PU-2023-8483
ALT-PU-2025-6317
BDU:2023-02497
BIT-JAVA-2023-21939
BIT-JAVA-MIN-2023-21939
BIT-JRE-2023-21939
CESA-2023_1875
CESA-2023_1895
CESA-2023_1898
CESA-2023_1904
CESA-2023_1908
CESA-2023_4103
CVE-2023-21939
DLA-3571-1
DSA-5430-1
DSA-5478-1
ELSA-2023-1875
ELSA-2023-1879
ELSA-2023-1880
ELSA-2023-1895
ELSA-2023-1898
ELSA-2023-1904
ELSA-2023-1908
ELSA-2023-1909
MGASA-2023-0272
OESA-2023-1600
OESA-2023-1601
OESA-2023-1602
OESA-2023-1603
OESA-2023-1617
OESA-2023-1618
OESA-2023-1642
OESA-2023-1643
OESA-2023-1644
OESA-2023-1645
OESA-2023-1646
OESA-2023-1650
OESA-2023-1737
OESA-2023-1738
OESA-2023-1739
OPENSUSE-SU-2023_3305-1
OPENSUSE-SU-2024:12891-1
OPENSUSE-SU-2024:12892-1
OPENSUSE-SU-2024:12909-1
OPENSUSE-SU-2025:0066-1
OPENSUSE-SU-2025:0067-1
RHSA-2023:1875
RHSA-2023:1877
RHSA-2023:1878
RHSA-2023:1879
RHSA-2023:1880
RHSA-2023:1889
RHSA-2023:1890
RHSA-2023:1891
RHSA-2023:1892
RHSA-2023:1895
RHSA-2023:1898
RHSA-2023:1899
RHSA-2023:1900
RHSA-2023:1904
RHSA-2023:1905
RHSA-2023:1906
RHSA-2023:1907
RHSA-2023:1908
RHSA-2023:1909
RHSA-2023:1910
RHSA-2023:1911
RHSA-2023:4103
RHSA-2023:4160
RHSA-2023_1875
RHSA-2023_1879
RHSA-2023_1880
RHSA-2023_1895
RHSA-2023_1898
RHSA-2023_1904
RHSA-2023_1908
RHSA-2023_1909
RHSA-2023_4103
RHSA-2023_4160
RLSA-2023:1879
RLSA-2023:1880
RLSA-2023:1895
RLSA-2023:1898
RLSA-2023:1909
RLSA-2023_1879
RLSA-2023_1880
RLSA-2023_1898
RLSA-2023_1909
ROSA-SA-2023-2213
SUSE-SU-2023:2109-1
SUSE-SU-2023:2110-1
SUSE-SU-2023:2222-1
SUSE-SU-2023:2238-1
SUSE-SU-2023:2242-1
SUSE-SU-2023:2242-2
SUSE-SU-2023:2476-1
SUSE-SU-2023:2491-1
SUSE-SU-2023:3305-1
SUSE-SU-2023_2109-1
SUSE-SU-2023_2110-1
SUSE-SU-2023_2222-1
SUSE-SU-2023_2238-1
SUSE-SU-2023_2242-1
SUSE-SU-2023_2242-2
SUSE-SU-2023_2476-1
SUSE-SU-2023_2491-1
USN-6077-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Ibm Aix
Java Platform
Linuxmint
Oracle Graalvm Enterprise Edition
Oracle Java Se
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu