First published: Mon Jul 15 2024(Updated: )
An unspecified vulnerability in Java SE related to the VM component could allow a remote attacker to cause a low availability impact.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
NetApp Active IQ Unified Manager for VMware vSphere | ||
NetApp BlueXP | ||
NetApp Data Infrastructure Insights Storage Workload Security Agent | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
Oracle GraalVM Enterprise Edition | =20.3.14 | |
Oracle GraalVM Enterprise Edition | =21.3.10 | |
Oracle GraalVM for JDK | =17.0.11 | |
Oracle GraalVM for JDK | =21.0.3 | |
Oracle GraalVM for JDK | =22.0.1 | |
Oracle JDK 6 | =1.8.0-update411 | |
Oracle JDK 6 | =1.8.0-update411 | |
Oracle JDK 6 | =11.0.23 | |
Oracle JDK 6 | =17.0.11 | |
Oracle JDK 6 | =21.0.3 | |
Oracle JDK 6 | =22.0.1 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update411 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update411 | |
Oracle Java Runtime Environment (JRE) | =11.0.23 | |
Oracle Java Runtime Environment (JRE) | =17.0.11 | |
Oracle Java Runtime Environment (JRE) | =21.0.3 | |
Oracle Java Runtime Environment (JRE) | =22.0.1 | |
debian/openjdk-11 | 11.0.24+8-2~deb11u1 11.0.26+4-1~deb11u1 11.0.26+4-1 | |
debian/openjdk-17 | 17.0.12+7-2~deb11u1 17.0.14+7-1~deb11u1 17.0.13+11-2~deb12u1 17.0.14+7-1~deb12u1 17.0.14+7-1 | |
debian/openjdk-21 | 21.0.6+7-1 | |
debian/openjdk-8 | 8u442-ga-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21138 has a low severity impact related to availability due to an infinite loop vulnerability.
To fix CVE-2024-21138, update your software to the latest patched version, such as OpenJDK 11.0.24+8 or OpenJDK 17.0.12+7.
CVE-2024-21138 affects various versions of Oracle JDK, Oracle JRE, GraalVM, and specific IBM and NetApp products.
Yes, CVE-2024-21138 can be exploited by a remote attacker, leading to low availability impacts.
CVE-2024-21138 involves the VM component of Java SE and excessive symbol lengths that trigger the vulnerability.