First published: Tue Oct 19 2021(Updated: )
An unspecified vulnerability in Java SE related to the JSSE component could allow an unauthenticated attacker to obtain sensitive information resulting in a high confidentiality impact using unknown attack vectors.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.8.0-openjdk-1:1.8.0.312.b07-1.el7_9 | 1.8.0-openjdk-1:1.8.0.312.b07-1.el7_9 |
redhat/java | <11-openjdk-1:11.0.13.0.8-1.el7_9 | 11-openjdk-1:11.0.13.0.8-1.el7_9 |
redhat/java | <1.8.0-ibm-1:1.8.0.7.5-1jpp.1.el7 | 1.8.0-ibm-1:1.8.0.7.5-1jpp.1.el7 |
redhat/java | <1.7.1-ibm-1:1.7.1.5.5-1jpp.1.el7 | 1.7.1-ibm-1:1.7.1.5.5-1jpp.1.el7 |
redhat/java | <11-openjdk-1:11.0.13.0.8-1.el8_4 | 11-openjdk-1:11.0.13.0.8-1.el8_4 |
redhat/java | <1.8.0-openjdk-1:1.8.0.312.b07-1.el8_4 | 1.8.0-openjdk-1:1.8.0.312.b07-1.el8_4 |
redhat/java | <1.8.0-ibm-1:1.8.0.7.5-1.el8_5 | 1.8.0-ibm-1:1.8.0.7.5-1.el8_5 |
redhat/java | <1.8.0-openjdk-1:1.8.0.312.b07-1.el8_1 | 1.8.0-openjdk-1:1.8.0.312.b07-1.el8_1 |
redhat/java | <11-openjdk-1:11.0.13.0.8-1.el8_1 | 11-openjdk-1:11.0.13.0.8-1.el8_1 |
redhat/java | <1.8.0-openjdk-1:1.8.0.312.b07-1.el8_2 | 1.8.0-openjdk-1:1.8.0.312.b07-1.el8_2 |
redhat/java | <11-openjdk-1:11.0.13.0.8-1.el8_2 | 11-openjdk-1:11.0.13.0.8-1.el8_2 |
debian/openjdk-11 | 11.0.16+8-1~deb10u1 11.0.20+8-1~deb10u1 11.0.20+8-1~deb11u1 11.0.21+9-1 | |
debian/openjdk-8 | 8u382-ga-2 | |
IBM InfoSphere Guardium z/OS | <=10.5 | |
IBM InfoSphere Guardium z/OS | <=10.6 | |
IBM InfoSphere Guardium z/OS | <=11.0 | |
IBM InfoSphere Guardium z/OS | <=11.1 | |
IBM InfoSphere Guardium z/OS | <=11.3 | |
IBM InfoSphere Guardium z/OS | <=11.2 | |
IBM InfoSphere Guardium z/OS | <=11.4 | |
Oracle GraalVM Enterprise Edition | =20.3.3 | |
Oracle GraalVM Enterprise Edition | =21.2.0 | |
OpenJDK 8 | =7-update311 | |
OpenJDK 8 | =8-update301 | |
OpenJDK 8 | =11.0.12 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
NetApp Active IQ Unified Manager | ||
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.50.2 | |
NetApp SANtricity Storage Manager | ||
NetApp E-Series SANtricity Web Services | ||
NetApp SolidFire & HCI Management Node | ||
NetApp OnCommand Insight | ||
NetApp E-Series SANtricity Unified Manager | ||
NetApp SnapManager for Oracle | ||
NetApp SnapManager for SAP | ||
NetApp SolidFire & HCI Storage Node | ||
Red Hat Fedora | =33 | |
Red Hat Fedora | =34 | |
Red Hat Fedora | =35 | |
Debian Linux | =9.0 | |
Debian Linux | =10.0 | |
Debian Linux | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-35550 is a vulnerability in the Java SE Oracle GraalVM Enterprise Edition product of Oracle Java SE.
Java SE versions 7u311, 8u301, 11.0.12, and Oracle GraalVM Enterprise Edition versions 20.3.3 and 21.2.0 are affected.
CVE-2021-35550 has a severity rating of 5.9, which is considered medium.
To fix CVE-2021-35550, update to the following versions: Java SE 7u311, 8u301, or 11.0.12, or Oracle GraalVM Enterprise Edition 20.3.3 or 21.2.0.
You can find more information about CVE-2021-35550 at the following references: [reference 1](https://github.com/openjdk/jdk11u/commit/af4b37301d33723806c38cf8ae5d85b7fa7ef39f), [reference 2](https://bugs.openjdk.java.net/browse/JDK-8163326), [reference 3](https://www.oracle.com/java/technologies/javase/11-0-13-relnotes.html).