First published: Wed Jan 10 2024(Updated: )
An unspecified vulnerability in Java SE related to the VM component could allow a remote attacker to cause high confidentiality impact and high integrity impact.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Controller | <=11.0.0 - 11.0.1 | |
Oracle GraalVM Enterprise Edition | =20.3.12 | |
Oracle GraalVM Enterprise Edition | =21.3.8 | |
Oracle GraalVM Enterprise Edition | =22.3.4 | |
Oracle GraalVM for JDK | =17.0.9 | |
Oracle GraalVM for JDK | =21.0.1 | |
Oracle JDK 6 | =1.8.0-update391 | |
Oracle JDK 6 | =1.8.0-update391 | |
Oracle JDK 6 | =11.0.21 | |
Oracle JDK 6 | =17.0.9 | |
Oracle JDK 6 | =21.0.1 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update391 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update391 | |
Oracle Java Runtime Environment (JRE) | =11.0.21 | |
Oracle Java Runtime Environment (JRE) | =17.0.9 | |
Oracle Java Runtime Environment (JRE) | =21.0.1 | |
Debian GNU/Linux | =10.0 | |
netapp cloud insights acquisition unit | ||
NetApp Cloud Insights Storage Workload Security Agent | ||
NetApp OnCommand Insight | ||
debian/openjdk-11 | 11.0.24+8-2~deb11u1 11.0.26+4-1~deb11u1 11.0.26+4-1 | |
debian/openjdk-17 | 17.0.12+7-2~deb11u1 17.0.14+7-1~deb11u1 17.0.13+11-2~deb12u1 17.0.14+7-1~deb12u1 17.0.14+7-1 | |
debian/openjdk-21 | 21.0.6+7-1 | |
debian/openjdk-8 | 8u442-ga-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-20918 is rated as high, affecting confidentiality and integrity.
To fix CVE-2024-20918, update to the latest patched versions of affected software as specified in the vendor advisories.
CVE-2024-20918 affects multiple software, including specific versions of Oracle GraalVM, JDK, and IBM Cognos Controller.
Yes, CVE-2024-20918 can be exploited remotely by attackers to compromise confidentiality and integrity.
CVE-2024-20918 specifically impacts the VM component and the Hotspot component of OpenJDK due to missing range checks.