First published: Thu Oct 12 2023(Updated: )
A flaw was discovered in the CORBA component of OpenJDK in the way it performed deserialization of IOR (Interoperable Object Reference) string objects. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Credit: secalert_us@oracle.com secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/openjdk-8 | <8 | 8 |
ubuntu/openjdk-8 | <8 | 8 |
ubuntu/openjdk-8 | <8 | 8 |
ubuntu/openjdk-8 | <8 | 8 |
ubuntu/openjdk-8 | <8 | 8 |
ubuntu/openjdk-8 | <8 | 8 |
debian/openjdk-8 | 8u412-ga-1 | |
Oracle JDK | =1.8.0-update381 | |
Oracle JDK | =1.8.0-update381 | |
Oracle JRE | =1.8.0-update381 | |
Oracle JRE | =1.8.0-update381 | |
Netapp Cloud Insights Acquisition Unit | ||
Netapp Cloud Insights Storage Workload Security Agent | ||
IBM Cognos Controller | <=11.0.0 - 11.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Oracle Java SE vulnerability is CVE-2023-22067.
The CORBA component of Oracle Java SE is affected by this vulnerability.
The versions 8u381 and 8u381-perf of Oracle Java SE are affected by this vulnerability.
This vulnerability has a severity rating of medium (5.3) according to the Common Vulnerability Scoring System (CVSS).
An unauthenticated attacker with network access via CORBA can exploit this vulnerability.