First published: Tue Jul 19 2022(Updated: )
It was discovered that the computeNextExponential() method in the Libraries component of OpenJDK failed to comply with the documentation, returning sometimes negative numbers.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/openjdk-17 | 17.0.7+7-1~deb11u1 17.0.8+7-1~deb12u1 17.0.9+9-1 | |
Oracle GraalVM Enterprise Edition | =21.3.2 | |
Oracle GraalVM Enterprise Edition | =22.1.0 | |
Oracle JDK 6 | =17.0.3.1 | |
Oracle Java Runtime Environment (JRE) | =17.0.3.1 | |
azul zulu | =17.34 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
Debian Debian Linux | =11.0 | |
NetApp 7-Mode Transition Tool | ||
NetApp Active IQ Unified Manager for VMware vSphere | ||
netapp active iq unified manager windows | ||
netapp cloud insights acquisition unit | ||
netapp cloud secure agent | ||
netapp hci management node | ||
NetApp OnCommand Insight | ||
netapp solidfire | ||
netapp hci compute node |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21549 is a vulnerability in the Oracle Java SE and Oracle GraalVM Enterprise Edition products that allows unauthenticated attackers to exploit the system.
Oracle Java SE versions 17.0.3.1, 17.0.6+10-1~deb11u1, and 17.0.6+10-1, as well as Oracle GraalVM Enterprise Edition versions 21.3.2 and 22.1.0, are affected by CVE-2022-21549.
CVE-2022-21549 can be easily exploited by unauthenticated attackers.
The severity of CVE-2022-21549 is not specified.
To fix CVE-2022-21549, you should update your Oracle Java SE and Oracle GraalVM Enterprise Edition installations to the latest versions.