QID 376436

Date Published: 2022-03-03

QID 376436: Adopt OpenJDK Vulnerability Advisory: 2022/01/18

AdoptOpenJDK binaries and scripts are open source licensed. AdoptOpenJDK uses infrastructure, build and test scripts to produce prebuilt binaries from OpenJDK class libraries.

Affected Version
Adopt OpenJDK versions 17.0.1, 15.0.5, 13.0.9, 11.0.13, 8u312, 7u321 and prior

QID Detection Logic (Authenticated):
This QID checks for the file or product version for Adopt OpenJDK

Exploitation could allow an attacker to impact the Availability of an affected system.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released updates to resolve these issues.

    Customers are advised to refer to vendor advisory OpenJDK Vulnerability Advisory: 2022/01/18

    Software Advisories
    Advisory ID Software Component Link
    OpenJDK Vulnerability Advisory: 2021/01/18 URL Logo mail.openjdk.java.net/pipermail/vuln-announce/2022-January/000014.html