QID 376423

Date Published: 2022-02-22

QID 376423: Adopt OpenJDK Vulnerability Advisory: 2021/04/20

AdoptOpenJDK binaries and scripts are open source licensed. AdoptOpenJDK uses infrastructure, build and test scripts to produce prebuilt binaries from OpenJDK class libraries.

CVE-2021-2163:vulnerability allows unauthenticated attacker with network access via multiple protocols.
CVE-2021-2161:It can be exploited by supplying untrusted data to APIs in the specified Component

Affected Version
Adopt OpenJDK versions 16,15.0.2, 13.0.6, 11.0.10, 8u282, 7u291 and prior

QID Detection Logic (Authenticated):
This QID checks for the file or product version for Adopt OpenJDK

Exploitation could allow an attacker to impact the Integrity of an affected system.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    The vendor has released updates to resolve these issues.

    Customers are advised to refer to vendor advisory OpenJDK Vulnerability Advisory: 2021/04/20

    CVEs related to QID 376423

    Software Advisories
    Advisory ID Software Component Link
    OpenJDK Vulnerability Advisory: 2021/04/20 URL Logo openjdk.java.net/groups/vulnerability/advisories/2021-04-20