QID 378495

Date Published: 2023-05-29

QID 378495: Red Hat OpenJDK 8u332 Windows Builds release and Security Update (RHSA-2022:1492)

This release of the Red Hat build of OpenJDK 8 (8u332) for Windows serves as a replacement for the Red Hat build of OpenJDK 8 (8u322) and includes security and bug fixes, and enhancements.

OpenJDK: Unbounded memory allocation when compiling crafted XPath expressions (JAXP, 8270504) (CVE-2022-21426).

OpenJDK: Missing check for negative ObjectIdentifier (Libraries, 8275151) (CVE-2022-21443).

OpenJDK: Improper object-to-string conversion in AnnotationInvocationHandler (Libraries, 8277672) (CVE-2022-21434).

OpenJDK: Defective secure validation in Apache Santuario (Libraries, 8278008) (CVE-2022-21476).

OpenJDK: URI parsing inconsistencies (JNDI, 8278972) (CVE-2022-21496).
Affected Versions:
Red Hat build of OpenJDK 8 (8u322) and later Versions and Prior to OpenJDK 8 (8u332)

QID Detection Logic (Authenticated)
This QID checks for the below registry keys HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" ,"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall and sub values to check Publisher and Display version.

Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    For more information regarding the update RHSA-2022:1492
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    RHSA-2022:1492 URL Logo access.redhat.com/errata/RHSA-2022:1492