First published: Tue Oct 18 2022(Updated: )
Java SE is vulnerable to a denial of service, caused by a flaw in the Lightweight HTTP Server. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Business Automation | <=V22.0.2 | |
IBM Cloud Pak for Business Automation | <=V21.0.3 - V21.0.3-IF016 | |
IBM Cloud Pak for Business Automation | <=V22.0.1 - V22.0.1-IF006 and later fixes V21.0.2 - V21.0.2-IF012 and later fixesV21.0.1 - V21.0.1-IF007 and later fixesV20.0.1 - V20.0.3 and later fixesV19.0.1 - V19.0.3 and later fixesV18.0.0 - V18.0.2 and later fixes | |
Oracle GraalVM | =20.3.7 | |
Oracle GraalVM | =21.3.3 | |
Oracle GraalVM | =22.2.0 | |
Oracle JDK | =1.8.0-update341 | |
Oracle JDK | =1.8.0-update345 | |
Oracle JDK | =11.0.16.1 | |
Oracle JDK | =17.0.4.1 | |
Oracle JDK | =19 | |
Oracle JRE | =1.8.0-update341 | |
Oracle JRE | =1.8.0-update345 | |
Oracle JRE | =11.0.16.1 | |
Oracle JRE | =17.0.4.1 | |
Oracle JRE | =19 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
NetApp 7-Mode Transition Tool | ||
Netapp Cloud Insights Acquisition Unit | ||
Netapp Cloud Secure Agent | ||
NetApp E-Series SANtricity OS Controller | >=11.0<=11.70.2 | |
Netapp E-series Santricity Storage Manager | ||
Netapp E-series Santricity Unified Manager | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
Netapp Santricity Storage Plugin Vcenter | ||
NetApp SANtricity Web Services Proxy | ||
Azul Zulu | =6.49 | |
Azul Zulu | =7.56 | |
Azul Zulu | =8.64 | |
Azul Zulu | =11.58 | |
Azul Zulu | =13.50 | |
Azul Zulu | =15.42 | |
Azul Zulu | =17.36 | |
Azul Zulu | =19.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21628 is a vulnerability in the Lightweight HTTP Server component of Oracle Java SE and Oracle GraalVM Enterprise Edition.
The severity of CVE-2022-21628 is medium with a CVSS score of 5.3.
The affected versions of Oracle Java SE are 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, and 19.
The affected versions of Oracle GraalVM Enterprise Edition are 20.3.7, 21.3.3, and 22.2.0.
To fix CVE-2022-21628, update to the patched versions of Oracle Java SE and Oracle GraalVM Enterprise Edition.