First published: Tue Oct 18 2022(Updated: )
Java SE is vulnerable to a denial of service, caused by a flaw in the Lightweight HTTP Server. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Business Automation | <=V22.0.2 | |
IBM Cloud Pak for Business Automation | <=V21.0.3 - V21.0.3-IF016 | |
IBM Cloud Pak for Business Automation | <=V22.0.1 - V22.0.1-IF006 and later fixes V21.0.2 - V21.0.2-IF012 and later fixesV21.0.1 - V21.0.1-IF007 and later fixesV20.0.1 - V20.0.3 and later fixesV19.0.1 - V19.0.3 and later fixesV18.0.0 - V18.0.2 and later fixes | |
Oracle GraalVM Enterprise Edition | =20.3.7 | |
Oracle GraalVM Enterprise Edition | =21.3.3 | |
Oracle GraalVM Enterprise Edition | =22.2.0 | |
Oracle JDK 6 | =1.8.0-update341 | |
Oracle JDK 6 | =1.8.0-update345 | |
Oracle JDK 6 | =11.0.16.1 | |
Oracle JDK 6 | =17.0.4.1 | |
Oracle JDK 6 | =19 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update341 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update345 | |
Oracle Java Runtime Environment (JRE) | =11.0.16.1 | |
Oracle Java Runtime Environment (JRE) | =17.0.4.1 | |
Oracle Java Runtime Environment (JRE) | =19 | |
Fedora | =35 | |
Fedora | =36 | |
NetApp 7-Mode Transition Tool | ||
netapp cloud insights acquisition unit | ||
netapp cloud secure agent | ||
NetApp E-Series SANtricity OS Controller | >=11.0<=11.70.2 | |
netapp e-series santricity storage manager | ||
netapp e-series santricity unified manager | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
NetApp SANtricity Storage Plugin for vCenter | ||
NetApp E-Series SANtricity Web Services Proxy | ||
Azul Systems Zulu | =6.49 | |
Azul Systems Zulu | =7.56 | |
Azul Systems Zulu | =8.64 | |
Azul Systems Zulu | =11.58 | |
Azul Systems Zulu | =13.50 | |
Azul Systems Zulu | =15.42 | |
Azul Systems Zulu | =17.36 | |
Azul Systems Zulu | =19.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21628 is a vulnerability in the Lightweight HTTP Server component of Oracle Java SE and Oracle GraalVM Enterprise Edition.
The severity of CVE-2022-21628 is medium with a CVSS score of 5.3.
The affected versions of Oracle Java SE are 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, and 19.
The affected versions of Oracle GraalVM Enterprise Edition are 20.3.7, 21.3.3, and 22.2.0.
To fix CVE-2022-21628, update to the patched versions of Oracle Java SE and Oracle GraalVM Enterprise Edition.