CVE-2021-35550: Medium severity IBM Security Guardium vulnerability

Published Oct 19, 2021
·
Updated

An unspecified vulnerability in Java SE related to the JSSE component could allow an unauthenticated attacker to obtain sensitive information resulting in a high confidentiality impact using unknown attack vectors.

Other sources

It was discovered that the default TLS cipher suite configuration in the JSSE component of OpenJDK preferred certain weak ciphers over stronger ciphers. This issue was addressed by:

- Preferring ciphers with forward secrecy. - Lowering priority of ciphers using RSA encryption key exchange. - Lowering priority of ciphers using SHA-1 hashing algorithm.

Upstream commit:

https://github.com/openjdk/jdk11u/commit/af4b37301d33723806c38cf8ae5d85b7fa7ef39f

Red Hat

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).

Affected Software

42 affected componentsFixes available
redhat/java<1.8.0-openjdk-1:1.8.0.312.b07-1.el7_9
1.8.0-openjdk-1:1.8.0.312.b07-1.el7_9
redhat/java<11-openjdk-1:11.0.13.0.8-1.el7_9
11-openjdk-1:11.0.13.0.8-1.el7_9
redhat/java<1.8.0-ibm-1:1.8.0.7.5-1jpp.1.el7
1.8.0-ibm-1:1.8.0.7.5-1jpp.1.el7
redhat/java<1.7.1-ibm-1:1.7.1.5.5-1jpp.1.el7
1.7.1-ibm-1:1.7.1.5.5-1jpp.1.el7
redhat/java<11-openjdk-1:11.0.13.0.8-1.el8_4
11-openjdk-1:11.0.13.0.8-1.el8_4
redhat/java<1.8.0-openjdk-1:1.8.0.312.b07-1.el8_4
1.8.0-openjdk-1:1.8.0.312.b07-1.el8_4
redhat/java<1.8.0-ibm-1:1.8.0.7.5-1.el8_5
1.8.0-ibm-1:1.8.0.7.5-1.el8_5
redhat/java<1.8.0-openjdk-1:1.8.0.312.b07-1.el8_1
1.8.0-openjdk-1:1.8.0.312.b07-1.el8_1
redhat/java<11-openjdk-1:11.0.13.0.8-1.el8_1
11-openjdk-1:11.0.13.0.8-1.el8_1
redhat/java<1.8.0-openjdk-1:1.8.0.312.b07-1.el8_2
1.8.0-openjdk-1:1.8.0.312.b07-1.el8_2
redhat/java<11-openjdk-1:11.0.13.0.8-1.el8_2
11-openjdk-1:11.0.13.0.8-1.el8_2
debian/openjdk-11
11.0.16+8-1~deb10u111.0.20+8-1~deb10u111.0.20+8-1~deb11u111.0.21+9-1
debian/openjdk-8
8u382-ga-2
IBM Security Guardium<=10.5
IBM Security Guardium<=10.6
IBM Security Guardium<=11.0
IBM Security Guardium<=11.1
IBM Security Guardium<=11.3
IBM Security Guardium<=11.2
IBM Security Guardium<=11.4
Oracle GraalVM=20.3.3
Oracle GraalVM=21.2.0
Oracle OpenJDK=7-update311
Oracle OpenJDK=8-update301
Oracle OpenJDK=11.0.12
NetApp Active Iq Unified Manager Vmware Vsphere
NetApp Active Iq Unified Manager Windows
NetApp E-Series SANtricity OS Controller>=11.0.0<=11.50.2
NetApp E-series Santricity Storage Manager
NetApp E-series Santricity Web Services Web Services Proxy
NetApp Hci Management Node
NetApp OnCommand Insight
NetApp Santricity Unified Manager
NetApp Snapmanager Oracle
NetApp Snapmanager Sap
NetApp Solidfire
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/java to a version that resolves this vulnerability.

    Fixed in 1.8.0-openjdk-1:1.8.0.312.b07-1.el7_9
  2. Upgrade

    Upgrade redhat/java to a version that resolves this vulnerability.

    Fixed in 11-openjdk-1:11.0.13.0.8-1.el7_9
  3. Upgrade

    Upgrade redhat/java to a version that resolves this vulnerability.

    Fixed in 1.8.0-ibm-1:1.8.0.7.5-1jpp.1.el7
  4. Upgrade

    Upgrade redhat/java to a version that resolves this vulnerability.

    Fixed in 1.7.1-ibm-1:1.7.1.5.5-1jpp.1.el7
  5. Upgrade

    Upgrade redhat/java to a version that resolves this vulnerability.

    Fixed in 11-openjdk-1:11.0.13.0.8-1.el8_4
  6. Upgrade

    Upgrade redhat/java to a version that resolves this vulnerability.

    Fixed in 1.8.0-openjdk-1:1.8.0.312.b07-1.el8_4
  7. Upgrade

    Upgrade redhat/java to a version that resolves this vulnerability.

    Fixed in 1.8.0-ibm-1:1.8.0.7.5-1.el8_5
  8. Upgrade

    Upgrade redhat/java to a version that resolves this vulnerability.

    Fixed in 1.8.0-openjdk-1:1.8.0.312.b07-1.el8_1
  9. Upgrade

    Upgrade redhat/java to a version that resolves this vulnerability.

    Fixed in 11-openjdk-1:11.0.13.0.8-1.el8_1
  10. Upgrade

    Upgrade redhat/java to a version that resolves this vulnerability.

    Fixed in 1.8.0-openjdk-1:1.8.0.312.b07-1.el8_2
  11. Upgrade

    Upgrade redhat/java to a version that resolves this vulnerability.

    Fixed in 11-openjdk-1:11.0.13.0.8-1.el8_2
  12. Upgrade

    Upgrade debian/openjdk-11 to a version that resolves this vulnerability.

    Fixed in 11.0.16+8-1~deb10u1Fixed in 11.0.20+8-1~deb10u1Fixed in 11.0.20+8-1~deb11u1Fixed in 11.0.21+9-1
  13. Upgrade

    Upgrade debian/openjdk-8 to a version that resolves this vulnerability.

    Fixed in 8u382-ga-2
  14. Upgrade

    Upgrade debian/openjdk-11 to a version that resolves this vulnerability.

    Fixed in 11.0.16+8-1~deb10u1
  15. Upgrade

    Upgrade debian/openjdk-11 to a version that resolves this vulnerability.

    Fixed in 11.0.20+8-1~deb10u1
  16. Upgrade

    Upgrade debian/openjdk-11 to a version that resolves this vulnerability.

    Fixed in 11.0.20+8-1~deb11u1
  17. Upgrade

    Upgrade debian/openjdk-11 to a version that resolves this vulnerability.

    Fixed in 11.0.21+9-1
  18. Configuration

    Adjust the JSSE/TLS cipher suite preference list to prefer forward-secret ciphers and de-prioritize RSA key-exchange and SHA-1 based ciphers (match the upstream change that prefers forward secrecy and lowers RSA/SHA-1 priority).

    JSSE (Java Secure Socket Extension) default TLS cipher suite ordering = prefer ciphers with forward secrecy; lower priority for RSA key-exchange and for ciphers using SHA-1
  19. Compensating control

    If you cannot apply provided fixed packages immediately, restrict network access to TLS services running on affected Java runtimes to trusted hosts/networks (firewall/ACL) and monitor TLS endpoints for suspicious connections until upgrades or configuration changes are applied.

Event History

Oct 19, 2021
CVE Published
12:00 AM
Data Sourced
via Red Hat·06:35 PM
DescriptionSeverityAffected Software
Oct 20, 2021
CVE Published
via MITRE·10:49 AM
Data Sourced
via MITRE·10:49 AM
DescriptionSeverityWeakness
Apr 29, 2022
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2021-35550?

CVE-2021-35550 is a vulnerability in the Java SE Oracle GraalVM Enterprise Edition product of Oracle Java SE.

2

Which versions of Java SE and Oracle GraalVM Enterprise Edition are affected?

Java SE versions 7u311, 8u301, 11.0.12, and Oracle GraalVM Enterprise Edition versions 20.3.3 and 21.2.0 are affected.

3

How severe is CVE-2021-35550?

CVE-2021-35550 has a severity rating of 5.9, which is considered medium.

4

How can I fix CVE-2021-35550?

To fix CVE-2021-35550, update to the following versions: Java SE 7u311, 8u301, or 11.0.12, or Oracle GraalVM Enterprise Edition 20.3.3 or 21.2.0.

5

Where can I find more information about CVE-2021-35550?

You can find more information about CVE-2021-35550 at the following references: [reference 1](https://github.com/openjdk/jdk11u/commit/af4b37301d33723806c38cf8ae5d85b7fa7ef39f), [reference 2](https://bugs.openjdk.java.net/browse/JDK-8163326), [reference 3](https://www.oracle.com/java/technologies/javase/11-0-13-relnotes.html).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203