Логотип exploitDog
bind:"GHSA-cjp9-fpg3-7wj6" OR bind:"CVE-2022-21296"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-cjp9-fpg3-7wj6" OR bind:"CVE-2022-21296"

Количество 29

Количество 29

github логотип

GHSA-cjp9-fpg3-7wj6

почти 4 года назад

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the A...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-21296

почти 4 года назад

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the ...

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-21296

почти 4 года назад

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-21296

почти 4 года назад

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the API

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2022-21296

почти 4 года назад

Vulnerability in the Oracle Java SE Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321 8u311 11.0.13 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments typically in clients running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code (e.g. code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component e.g. through a web service which supplies data to the APIs. CVSS 3.1

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-21296

почти 4 года назад

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition ...

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2022-01985

почти 4 года назад

Уязвимость компонента JAXP программной платформы Oracle Java SE и виртуальной машины Oracle GraalVM Enterprise Edition, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.3
EPSS: Низкий
oracle-oval логотип

ELSA-2022-0307

почти 4 года назад

ELSA-2022-0307: java-1.8.0-openjdk security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-0306

почти 4 года назад

ELSA-2022-0306: java-1.8.0-openjdk security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0873-1

больше 3 лет назад

Security update for java-1_8_0-openjdk

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0873-1

больше 3 лет назад

Security update for java-1_8_0-openjdk

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0871-1

больше 3 лет назад

Security update for java-1_8_0-openjdk

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0870-1

больше 3 лет назад

Security update for java-1_8_0-openj9

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0816-1

больше 3 лет назад

Security update for java-11-openjdk

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0816-1

больше 3 лет назад

Security update for java-11-openjdk

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0730-1

больше 3 лет назад

Security update for java-11-openjdk

EPSS: Низкий
rocky логотип

RLSA-2022:185

почти 4 года назад

Moderate: java-11-openjdk security update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-0204

почти 4 года назад

ELSA-2022-0204: java-11-openjdk security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-0185

почти 4 года назад

ELSA-2022-0185: java-11-openjdk security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-0161

почти 4 года назад

ELSA-2022-0161: java-17-openjdk security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-cjp9-fpg3-7wj6

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the A...

CVSS3: 5.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-21296

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the ...

CVSS3: 5.3
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-21296

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the ...

CVSS3: 5.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-21296

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the API

CVSS3: 5.3
0%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-21296

Vulnerability in the Oracle Java SE Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321 8u311 11.0.13 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments typically in clients running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code (e.g. code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component e.g. through a web service which supplies data to the APIs. CVSS 3.1

CVSS3: 5.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-21296

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition ...

CVSS3: 5.3
0%
Низкий
почти 4 года назад
fstec логотип
BDU:2022-01985

Уязвимость компонента JAXP программной платформы Oracle Java SE и виртуальной машины Oracle GraalVM Enterprise Edition, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.3
0%
Низкий
почти 4 года назад
oracle-oval логотип
ELSA-2022-0307

ELSA-2022-0307: java-1.8.0-openjdk security and bug fix update (MODERATE)

почти 4 года назад
oracle-oval логотип
ELSA-2022-0306

ELSA-2022-0306: java-1.8.0-openjdk security update (MODERATE)

почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2022:0873-1

Security update for java-1_8_0-openjdk

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0873-1

Security update for java-1_8_0-openjdk

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0871-1

Security update for java-1_8_0-openjdk

больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0870-1

Security update for java-1_8_0-openj9

больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0816-1

Security update for java-11-openjdk

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0816-1

Security update for java-11-openjdk

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0730-1

Security update for java-11-openjdk

больше 3 лет назад
rocky логотип
RLSA-2022:185

Moderate: java-11-openjdk security update

почти 4 года назад
oracle-oval логотип
ELSA-2022-0204

ELSA-2022-0204: java-11-openjdk security update (MODERATE)

почти 4 года назад
oracle-oval логотип
ELSA-2022-0185

ELSA-2022-0185: java-11-openjdk security update (MODERATE)

почти 4 года назад
oracle-oval логотип
ELSA-2022-0161

ELSA-2022-0161: java-17-openjdk security update (MODERATE)

почти 4 года назад

Уязвимостей на страницу