CVE-2023-21835
Summary
| CVE | CVE-2023-21835 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-18 00:15:00 UTC |
| Updated | 2024-01-17 15:15:00 UTC |
| Description | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.17, 17.0.5, 19.0.1; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via DTLS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Azul | Zulu | 11.60 | All | All | All |
| Application | Azul | Zulu | 13.52 | All | All | All |
| Application | Azul | Zulu | 15.44 | All | All | All |
| Application | Azul | Zulu | 17.38 | All | All | All |
| Application | Azul | Zulu | 19.30 | All | All | All |
| Application | Oracle | Graalvm | 20.3.8 | All | All | All |
| Application | Oracle | Graalvm | 21.3.4 | All | All | All |
| Application | Oracle | Graalvm | 22.3.0 | All | All | All |
| Application | Oracle | Jdk | 11.0.17 | All | All | All |
| Application | Oracle | Jdk | 17.0.5 | All | All | All |
| Application | Oracle | Jdk | 19.0.1 | All | All | All |
| Application | Oracle | Jre | 11.0.17 | All | All | All |
| Application | Oracle | Jre | 17.0.5 | All | All | All |
| Application | Oracle | Jre | 19.0.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| OpenJDK: Multiple Vulnerabilities (GLSA 202401-25) — Gentoo security | security.gentoo.org | ||
| Oracle Critical Patch Update Advisory - January 2023 | MISC | www.oracle.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160399 Oracle Enterprise Linux Security Update for java-17-openjdk (ELSA-2023-0192)
- 160400 Oracle Enterprise Linux Security Update for java-11-openjdk (ELSA-2023-0200)
- 160401 Oracle Enterprise Linux Security Update for java-11-openjdk (ELSA-2023-0202)
- 160404 Oracle Enterprise Linux Security Update for java-17-openjdk (ELSA-2023-0194)
- 160418 Oracle Enterprise Linux Security Update for java-11-openjdk (ELSA-2023-0195)
- 181513 Debian Security Update for openjdk-11 (DSA 5331-1)
- 181535 Debian Security Update for openjdk-17 (DSA 5335-1)
- 181541 Debian Security Update for openjdk-11 (DLA 3307-1)
- 182206 Debian Security Update for openjdk-17 (CVE-2023-21835)
- 199194 Ubuntu Security Notification for Open Java Development Toolkit (OpenJDK) Vulnerabilities (USN-5897-1)
- 241071 Red Hat Update for java-11-openjdk (RHSA-2023:0201)
- 241072 Red Hat Update for java-11-openjdk (RHSA-2023:0202)
- 241073 Red Hat Update for java-11-openjdk (RHSA-2023:0198)
- 241075 Red Hat Update for java-17-openjdk (RHSA-2023:0191)
- 241076 Red Hat Update for java-11-openjdk (RHSA-2023:0200)
- 241077 Red Hat Update for java-17-openjdk (RHSA-2023:0192)
- 241078 Red Hat Update for java-17-openjdk (RHSA-2023:0190)
- 241079 Red Hat Update for java-11-openjdk (RHSA-2023:0199)
- 241080 Red Hat Update for java-17-openjdk (RHSA-2023:0193)
- 241085 Red Hat Update for java-17-openjdk (RHSA-2023:0194)
- 241091 Red Hat Update for java-11-openjdk (RHSA-2023:0195)
- 241693 Red Hat Update for java-11-openjdk (RHSA-2023:0196)
- 241696 Red Hat Update for java-11-openjdk (RHSA-2023:0197)
- 257213 CentOS Security Update for java-11-openjdk (CESA-2023:0195)
- 283654 Fedora Security Update for java (FEDORA-2023-585aca2233)
- 283679 Fedora Security Update for java (FEDORA-2023-327768681a)
- 283680 Fedora Security Update for java (FEDORA-2023-d6bd6ec00b)
- 283681 Fedora Security Update for java (FEDORA-2023-df5421d170)
- 283682 Fedora Security Update for java (FEDORA-2023-43bce108c7)
- 283683 Fedora Security Update for java (FEDORA-2023-097f828f8c)
- 354652 Amazon Linux Security Advisory for java-11-amazon-corretto : ALAS2-2023-1918
- 354661 Amazon Linux Security Advisory for java-17-amazon-corretto : ALAS2-2023-1919
- 354698 Amazon Linux Security Advisory for java-17-amazon-corretto : ALAS2022-2023-281
- 354713 Amazon Linux Security Advisory for java-11-amazon-corretto : ALAS2022-2023-280
- 354773 Amazon Linux Security Advisory for java-11-openjdk : ALAS2JAVA-OPENJDK11-2023-003
- 377904 Oracle Java Standard Edition (SE) Critical Patch Update - January 2023 (CPUJAN2023)
- 377930 Azul Java Multiple Vulnerabilities Security Update January 2023
- 377933 Amazon Corretto Critical Patch Update (JAN2023)
- 377947 Alibaba Cloud Linux Security Update for java-11-openjdk (ALINUX2-SA-2023:0008)
- 378122 Alibaba Cloud Linux Security Update for java-11-openjdk (ALINUX3-SA-2023:0030)
- 378350 Red Hat OpenJDK 17.0.6 Security Update for Windows Builds (RHSA-2023:0352)
- 378351 Red Hat OpenJDK 11.0.18 Security Update for Windows Builds (RHSA-2023:0353)
- 502642 Alpine Linux Security Update for openjdk11
- 502643 Alpine Linux Security Update for openjdk17
- 506139 Alpine Linux Security Update for openjdk19
- 710843 Gentoo Linux Open Java Development Toolkit (OpenJDK) Multiple Vulnerabilities (GLSA 202401-25)
- 753711 SUSE Enterprise Linux Security Update for java-11-openjdk (SUSE-SU-2023:0436-1)
- 753712 SUSE Enterprise Linux Security Update for java-17-openjdk (SUSE-SU-2023:0435-1)
- 753798 SUSE Enterprise Linux Security Update for java-11-openjdk (SUSE-SU-2023:0752-1)
- 753912 SUSE Enterprise Linux Security Update for java-1_8_0-ibm (SUSE-SU-2023:1850-1)
- 754000 SUSE Enterprise Linux Security Update for java-1_8_0-ibm (SUSE-SU-2023:1823-1)
- 940885 AlmaLinux Security Update for java-17-openjdk (ALSA-2023:0192)
- 940886 AlmaLinux Security Update for java-11-openjdk (ALSA-2023:0200)
- 940887 AlmaLinux Security Update for java-11-openjdk (ALSA-2023:0202)
- 940891 AlmaLinux Security Update for java-17-openjdk (ALSA-2023:0194)
- 960512 Rocky Linux Security Update for java-17-openjdk (RLSA-2023:0194)
- 960521 Rocky Linux Security Update for java-11-openjdk (RLSA-2023:0202)
- 960536 Rocky Linux Security Update for java-11-openjdk (RLSA-2023:0200)
- 960544 Rocky Linux Security Update for java-17-openjdk (RLSA-2023:0192)