PT-2023-6270 · Oracle+9 · Oracle Java Se+11

Bing

+1

·

Published

2023-10-17

·

Updated

2026-05-08

·

CVE-2023-22067

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 8u381 through 8u381-perf Oracle GraalVM Enterprise Edition versions 20.3.11 through 21.3.7
Description The vulnerability in the Oracle Java SE and Oracle GraalVM Enterprise Edition product is related to the CORBA component. It allows an unauthenticated attacker with network access via CORBA to compromise the system. Successful attacks can result in unauthorized update, insert, or delete access to some of the accessible data. This vulnerability can only be exploited by supplying data to APIs in the specified component without using untrusted Java Web Start applications or untrusted Java applets, such as through a web service.
Recommendations For Oracle Java SE versions 8u381 through 8u381-perf, consider disabling the CORBA component until a patch is available. For Oracle GraalVM Enterprise Edition versions 20.3.11 through 21.3.7, restrict access to the CORBA component to minimize the risk of exploitation. As a temporary workaround, consider restricting the use of APIs in the specified component without using untrusted Java Web Start applications or untrusted Java applets. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

RCE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

ALSA-2023:5731
ALSA-2023:5733
ALT-PU-2024-17587
ALT-PU-2024-17589
ALT-PU-2024-17592
ALT-PU-2025-6317
BDU:2023-06980
BIT-JAVA-2023-22067
BIT-JAVA-MIN-2023-22067
BIT-JRE-2023-22067
CESA-2023_5731
CESA-2023_5761
CESA-2024_0866
CVE-2023-22067
DSA-5537-1
MGASA-2023-0326
OESA-2023-1813
OESA-2023-1839
OPENSUSE-SU-2023_4506-1
OPENSUSE-SU-2024:13421-1
OPENSUSE-SU-2024:13457-1
RHSA-2023:5727
RHSA-2023:5728
RHSA-2023:5729
RHSA-2023:5730
RHSA-2023:5731
RHSA-2023:5732
RHSA-2023:5733
RHSA-2023:5761
RHSA-2023_5731
RHSA-2023_5733
RHSA-2023_5761
RHSA-2024:0866
RHSA-2024:0879
RHSA-2024_0866
RHSA-2024_0879
ROSA-SA-2023-2312
SUSE-SU-2023:4506-1
SUSE-SU-2023:4507-1
SUSE-SU-2023:4572-1
SUSE-SU-2023:4612-1
SUSE-SU-2023:4614-1
USN-6528-1

Affected Products

Alt Linux
Almalinux
Centos
Ibm Aix
Java Platform
Linuxmint
Oracle Graalvm Enterprise Edition
Oracle Java Se
Red Hat
Red Os
Suse
Ubuntu