• CVE-2023-22067

发布时间: 2023年11月10日

修改时间: 2023年11月17日

概要

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf; Oracle GraalVM Enterprise Edition: 20.3.11 and 21.3.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via CORBA to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).

CVSS v3 指标

NVD openEuler
CVSS评分 5.3 5.3
Attack Vector Network Network
Attack Complexity Low Low
Privileges Required None None
User Interaction None None
Scope Unchanged Unchanged
Confidentiality None None
Integrity Low Low
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2023-1953 openjdk-1.8.0 security update 2023年11月10日
KylinSec-SA-2023-2009 openjdk-1.8.0 security update 2023年11月17日

影响产品

产品 状态
KY3.4-4A openjdk-1.8.0 Fixed
KY3.4-5A openjdk-1.8.0 Fixed
KY3.5.1 openjdk-1.8.0 Fixed
KY3.5.2 openjdk-1.8.0 Fixed