PT-2023-6272 · Oracle+8 · Oracle Java Se+11

Carter Kozak

·

Published

2023-09-26

·

Updated

2026-05-08

·

CVE-2023-22025

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 8u381-perf, 17.0.8, 21 Oracle GraalVM for JDK versions 17.0.8, 21 Oracle GraalVM Enterprise Edition versions 21.3.7, 22.3.3
Description A difficult to exploit vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition allows an unauthenticated attacker with network access via multiple protocols to compromise these products. Successful attacks can result in unauthorized update, insert, or delete access to some accessible data. This vulnerability can be exploited by using APIs in the specified component, e.g., through a web service that supplies data to the APIs. It also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code and rely on the Java sandbox for security.
Recommendations For Oracle Java SE version 8u381-perf, update to a newer version to mitigate the risk. For Oracle Java SE versions 17.0.8, 21, update to a newer version to mitigate the risk. For Oracle GraalVM for JDK versions 17.0.8, 21, update to a newer version to mitigate the risk. For Oracle GraalVM Enterprise Edition versions 21.3.7, 22.3.3, update to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the vulnerable APIs until a patch is available.

Fix

RCE

Weakness Enumeration

Related Identifiers

ALSA-2023:5751
ALSA-2023:5753
ALSA-2023:6738
ALSA-2023:6887
ALT-PU-2023-8490
ALT-PU-2023-8491
ALT-PU-2023-8493
ALT-PU-2023-8495
ALT-PU-2024-17574
BDU:2023-06982
BIT-JAVA-2023-22025
BIT-JAVA-MIN-2023-22025
BIT-JRE-2023-22025
CESA-2023_5751
CESA-2023_6887
CVE-2023-22025
DSA-5548-1
MGASA-2024-0056
OESA-2023-1814
OESA-2023-1815
OESA-2023-1829
OESA-2024-2485
OESA-2024-2486
OESA-2024-2488
OESA-2024-2489
OPENSUSE-SU-2023_4289-1
OPENSUSE-SU-2024:13351-1
OPENSUSE-SU-2024:13357-1
OPENSUSE-SU-2024:13456-1
OPENSUSE-SU-2025:0067-1
RHSA-2023:5747
RHSA-2023:5750
RHSA-2023:5751
RHSA-2023:5752
RHSA-2023:5753
RHSA-2023:6738
RHSA-2023:6887
RHSA-2023_5751
RHSA-2023_5753
RHSA-2023_6738
RHSA-2023_6887
SUSE-SU-2023:4289-1
SUSE-SU-2023:4572-1
SUSE-SU-2023:4614-1
SUSE-SU-2023_4289-1
SUSE-SU-2023_4572-1
SUSE-SU-2023_4614-1
USN-6527-1
USN-6528-1

Affected Products

Alt Linux
Almalinux
Centos
Confluence
Java Platform
Linuxmint
Oracle Graalvm Enterprise Edition
Oracle Graalvm For Jdk
Oracle Java Se
Red Hat
Suse
Ubuntu