QID 378368

Date Published: 2023-04-18

QID 378368: Red Hat OpenJDK 8u352 Windows Builds release and Security Update (RHSA-2022:7049)

The OpenJDK 8 packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.

OpenJDK: improper handling of long NTLM client hostnames (Networking, 8286526) (CVE-2022-21619).

OpenJDK: excessive memory allocation in X.509 certificate parsing (Libraries, 8286533) (CVE-2022-21626).

OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910) (CVE-2022-21624).

OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) (CVE-2022-21628).
Affected Versions:
Red Hat build of OpenJDK 8 (8u342) and later Versions and Prior to OpenJDK 8 (8u352)

QID Detection Logic (Authenticated)
This QID checks for the below registry keys HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" ,"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall and sub values to check Publisher and Display version.

Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS).

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    For more information regarding the update RHSA-2022:7049
    Vendor References

    CVEs related to QID 378368

    Software Advisories
    Advisory ID Software Component Link
    RHSA-2022:7049 URL Logo access.redhat.com/errata/RHSA-2022:7049