First published: Fri Oct 15 2021(Updated: )
An unspecified vulnerability in Java SE related to the JSSE component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.8.0-openjdk-1:1.8.0.312.b07-1.el7_9 | 1.8.0-openjdk-1:1.8.0.312.b07-1.el7_9 |
redhat/java | <11-openjdk-1:11.0.13.0.8-1.el7_9 | 11-openjdk-1:11.0.13.0.8-1.el7_9 |
redhat/java | <1.8.0-ibm-1:1.8.0.7.0-1jpp.1.el7 | 1.8.0-ibm-1:1.8.0.7.0-1jpp.1.el7 |
redhat/java | <1.7.1-ibm-1:1.7.1.5.0-1jpp.1.el7 | 1.7.1-ibm-1:1.7.1.5.0-1jpp.1.el7 |
redhat/java | <11-openjdk-1:11.0.13.0.8-1.el8_4 | 11-openjdk-1:11.0.13.0.8-1.el8_4 |
redhat/java | <1.8.0-openjdk-1:1.8.0.312.b07-1.el8_4 | 1.8.0-openjdk-1:1.8.0.312.b07-1.el8_4 |
redhat/java | <1.8.0-ibm-1:1.8.0.7.0-1.el8_5 | 1.8.0-ibm-1:1.8.0.7.0-1.el8_5 |
redhat/java | <1.8.0-openjdk-1:1.8.0.312.b07-1.el8_1 | 1.8.0-openjdk-1:1.8.0.312.b07-1.el8_1 |
redhat/java | <11-openjdk-1:11.0.13.0.8-1.el8_1 | 11-openjdk-1:11.0.13.0.8-1.el8_1 |
redhat/java | <1.8.0-openjdk-1:1.8.0.312.b07-1.el8_2 | 1.8.0-openjdk-1:1.8.0.312.b07-1.el8_2 |
redhat/java | <11-openjdk-1:11.0.13.0.8-1.el8_2 | 11-openjdk-1:11.0.13.0.8-1.el8_2 |
debian/openjdk-11 | 11.0.16+8-1~deb10u1 11.0.20+8-1~deb10u1 11.0.20+8-1~deb11u1 11.0.21+9-1 | |
debian/openjdk-8 | 8u382-ga-2 | |
IBM QRadar SIEM | <=7.5.0 GA | |
IBM QRadar SIEM | <=7.4.3 GA - 7.4.3 FP4 | |
IBM QRadar SIEM | <=7.3.3 GA - 7.3.3 FP10 | |
Oracle GraalVM Enterprise Edition | =20.3.3 | |
Oracle GraalVM Enterprise Edition | =21.2.0 | |
OpenJDK 17 | =7-update311 | |
OpenJDK 17 | =8-update301 | |
OpenJDK 17 | =11.0.12 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
netapp active iq unified manager windows | ||
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.50.2 | |
netapp e-series santricity storage manager | ||
netapp e-series santricity Web services Web services proxy | ||
netapp hci management node | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
netapp santricity unified manager | ||
netapp snapmanager Oracle | ||
netapp snapmanager sap | ||
netapp solidfire | ||
Fedora | =33 | |
Fedora | =34 | |
Fedora | =35 | |
Debian | =9.0 | |
Debian | =10.0 | |
Debian | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The severity of CVE-2021-35565 is high.
Java SE versions 7u311, 8u301, and 11.0.12 are affected by CVE-2021-35565.
CVE-2021-35565 can be exploited by an unauthenticated attacker.
The remedy for CVE-2021-35565 in Red Hat Java packages is to update to the specified versions: 1.8.0-openjdk-1:1.8.0.312.b07-1.el7_9 for Java 8, and 11-openjdk-1:11.0.13.0.8-1.el7_9 for Java 11.
To patch IBM QRadar SIEM for CVE-2021-35565, download the appropriate fix for your version from the provided URL.