QID 378497

Date Published: 2023-05-29

QID 378497: Red Hat OpenJDK 8u322 Windows Builds release and Security Update (RHSA-2022:0321)

This release of the Red Hat build of OpenJDK 8 (8u322) for Windows serves as a replacement for the Red Hat build of OpenJDK 8 (8u312) and includes security and bug fixes, and enhancements.

OpenJDK: Unexpected exception thrown in regex Pattern (Libraries, 8268813) (CVE-2022-21283).

OpenJDK: Incomplete checks of StringBuffer and StringBuilder during deserialization (Libraries, 8270392) (CVE-2022-21293).

OpenJDK: Incorrect IdentityHashMap size checks during deserialization (Libraries, 8270416) (CVE-2022-21294).

OpenJDK: Insufficient URI checks in the XSLT TransformerImpl (JAXP, 8270492) (CVE-2022-21282).

OpenJDK: Incorrect access checks in XMLEntityManager (JAXP, 8270498) (CVE-2022-21296).

OpenJDK: Infinite loop related to incorrect handling of newlines in XMLEntityScanner (JAXP, 8270646) (CVE-2022-21299).

OpenJDK: Excessive memory allocation in BMPImageReader (ImageIO, 8273756) (CVE-2022-21360).
Affected Versions:
Red Hat build of OpenJDK 8 (8u312) and later Versions and Prior to OpenJDK 8 (8u322)

QID Detection Logic (Authenticated)
This QID checks for the below registry keys HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" ,"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall and sub values to check Publisher and Display version.

Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS).

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    For more information regarding the update RHSA-2022:0321
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    RHSA-2022:0321 URL Logo access.redhat.com/errata/RHSA-2022:0321