QID 376757

Date Published: 2022-07-27

QID 376757: Adopt OpenJDK Vulnerability Advisory: 2022-04-19

AdoptOpenJDK binaries and scripts are open source licensed. AdoptOpenJDK uses infrastructure, build and test scripts to produce prebuilt binaries from OpenJDK class libraries.

Affected Version
Adopt OpenJDK versions 18, 17.0.2, 15.0.6, 13.0.10, 11.0.14, 8u322, 7u331 and prior

QID Detection Logic (Authenticated):
This QID checks for the file or product version for Adopt OpenJDK

Exploitation could allow an attacker to impact the confidentiality of an affected system.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released updates to resolve these issues.

    Customers are advised to refer to vendor advisory OpenJDK Vulnerability Advisory: 2022-04-19

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    OpenJDK 000015 URL Logo mail.openjdk.org/pipermail/vuln-announce/2022-April/000015.html