First published: Tue Jul 19 2022(Updated: )
It was discovered that the computeNextExponential() method in the Libraries component of OpenJDK failed to comply with the documentation, returning sometimes negative numbers.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/openjdk-17 | 17.0.7+7-1~deb11u1 17.0.8+7-1~deb12u1 17.0.9+9-1 | |
Oracle GraalVM | =21.3.2 | |
Oracle GraalVM | =22.1.0 | |
Oracle JDK | =17.0.3.1 | |
Oracle JRE | =17.0.3.1 | |
Azul Zulu | =17.34 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
Debian Debian Linux | =11.0 | |
NetApp 7-Mode Transition Tool | ||
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Active Iq Unified Manager Windows | ||
Netapp Cloud Insights Acquisition Unit | ||
Netapp Cloud Secure Agent | ||
Netapp Hci Management Node | ||
NetApp OnCommand Insight | ||
Netapp Solidfire | ||
Netapp Hci Compute Node |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21549 is a vulnerability in the Oracle Java SE and Oracle GraalVM Enterprise Edition products that allows unauthenticated attackers to exploit the system.
Oracle Java SE versions 17.0.3.1, 17.0.6+10-1~deb11u1, and 17.0.6+10-1, as well as Oracle GraalVM Enterprise Edition versions 21.3.2 and 22.1.0, are affected by CVE-2022-21549.
CVE-2022-21549 can be easily exploited by unauthenticated attackers.
The severity of CVE-2022-21549 is not specified.
To fix CVE-2022-21549, you should update your Oracle Java SE and Oracle GraalVM Enterprise Edition installations to the latest versions.