PT-2023-3456 · Oracle+9 · Oracle Java Se+11

Markus Loewe

·

Published

2023-01-17

·

Updated

2026-05-08

·

CVE-2023-21843

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 8u351, 8u351-perf, 11.0.17, 17.0.5, 19.0.1 Oracle GraalVM Enterprise Edition versions 20.3.8, 21.3.4, 22.3.0
Description A difficult to exploit vulnerability in the Oracle Java SE and Oracle GraalVM Enterprise Edition allows an unauthenticated attacker with network access via multiple protocols to compromise the system. Successful attacks can result in unauthorized update, insert, or delete access to some accessible data. This vulnerability applies to Java deployments in clients running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code and rely on the Java sandbox for security.
Recommendations For Oracle Java SE versions 8u351, 8u351-perf, 11.0.17, 17.0.5, 19.0.1, consider disabling the Sound component until a patch is available. For Oracle GraalVM Enterprise Edition versions 20.3.8, 21.3.4, 22.3.0, consider disabling the Sound component until a patch is available. As a temporary workaround, restrict access to the Sound component to minimize the risk of exploitation. Avoid using the affected Oracle Java SE and Oracle GraalVM Enterprise Edition versions in clients that load and run untrusted code. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:0192
ALSA-2023:0194
ALSA-2023:0200
ALSA-2023:0202
ALSA-2023:0208
ALSA-2023:0210
ALT-PU-2023-8449
ALT-PU-2023-8450
ALT-PU-2023-8452
ALT-PU-2023-8453
ALT-PU-2023-8454
ALT-PU-2023-8455
ALT-PU-2023-8460
ALT-PU-2023-8482
ALT-PU-2023-8483
ALT-PU-2025-6317
BDU:2023-03640
BIT-JAVA-2023-21843
BIT-JAVA-MIN-2023-21843
BIT-JRE-2023-21843
CESA-2023_0192
CESA-2023_0195
CESA-2023_0200
CESA-2023_0203
CESA-2023_0208
CVE-2023-21843
DLA-3307-1
DSA-5331-1
DSA-5335-1
MGASA-2023-0037
OESA-2023-1600
OESA-2023-1601
OESA-2023-1602
OESA-2023-1603
OESA-2023-1617
OESA-2023-1618
OESA-2023-1642
OESA-2023-1643
OESA-2023-1644
OESA-2023-1645
OESA-2023-1646
OESA-2023-1650
OESA-2023-1737
OESA-2023-1738
OESA-2023-1739
OPENSUSE-SU-2023_0435-1
OPENSUSE-SU-2024:12661-1
OPENSUSE-SU-2024:12663-1
OPENSUSE-SU-2024:12669-1
OPENSUSE-SU-2024:12670-1
OPENSUSE-SU-2024:12719-1
OPENSUSE-SU-2024:12720-1
OPENSUSE-SU-2024:12754-1
OPENSUSE-SU-2024:12755-1
OPENSUSE-SU-2025:0066-1
OPENSUSE-SU-2025:0067-1
RHSA-2023:0190
RHSA-2023:0191
RHSA-2023:0192
RHSA-2023:0193
RHSA-2023:0194
RHSA-2023:0195
RHSA-2023:0196
RHSA-2023:0197
RHSA-2023:0198
RHSA-2023:0199
RHSA-2023:0200
RHSA-2023:0201
RHSA-2023:0202
RHSA-2023:0203
RHSA-2023:0204
RHSA-2023:0205
RHSA-2023:0206
RHSA-2023:0207
RHSA-2023:0208
RHSA-2023:0209
RHSA-2023:0210
RHSA-2023:3136
RHSA-2023_0192
RHSA-2023_0194
RHSA-2023_0195
RHSA-2023_0200
RHSA-2023_0202
RHSA-2023_0203
RHSA-2023_0208
RHSA-2023_0210
RHSA-2023_3136
RLSA-2023:0192
RLSA-2023:0194
RLSA-2023:0200
RLSA-2023:0202
RLSA-2023:0208
RLSA-2023:0210
ROSA-SA-2023-2151
SUSE-SU-2023:0435-1
SUSE-SU-2023:0436-1
SUSE-SU-2023:0437-1
SUSE-SU-2023:0685-1
SUSE-SU-2023:0720-1
SUSE-SU-2023:0752-1
SUSE-SU-2023:1823-1
SUSE-SU-2023:1850-1
USN-5897-1
USN-5898-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Java Platform
Linuxmint
Oracle Graalvm Enterprise Edition
Oracle Java Se
Red Hat
Rocky Linux
Suse
Ubuntu