Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "1.8.0-update291"
}
],
"cpe": "cpe:2.3:a:oracle:jdk:1.8.0:update291:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.0.11"
}
],
"cpe": "cpe:2.3:a:oracle:jdk:11.0.11:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "16.0.1"
}
],
"cpe": "cpe:2.3:a:oracle:jdk:16.0.1:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "1.8.0-update291"
}
],
"cpe": "cpe:2.3:a:oracle:jre:1.8.0:update291:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.0.11"
}
],
"cpe": "cpe:2.3:a:oracle:jre:11.0.11:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "16.0.1"
}
],
"cpe": "cpe:2.3:a:oracle:jre:16.0.1:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.0.10"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.10:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.0.11"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.11:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.0.1"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.1:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.0.2"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.2:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.0.3"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.3:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.0.4"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.4:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.0.5"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.5:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.0.6"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.6:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.0.7"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.7:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.0.8"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.8:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.0.9"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.9:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "13.0.1"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:13.0.1:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "13.0.2"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:13.0.2:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "13.0.3"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:13.0.3:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "13.0.4"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:13.0.4:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "13.0.5"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:13.0.5:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "13.0.6"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:13.0.6:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "13.0.7"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:13.0.7:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "16.0.1"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:16.0.1:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-NA"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:-:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-milestone1"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone1:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-milestone2"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone2:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-milestone3"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone3:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-milestone4"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone4:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-milestone5"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone5:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-milestone6"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone6:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-milestone7"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone7:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-milestone8"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone8:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-milestone9"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone9:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update141"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update141:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update151"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update151:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update152"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update152:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update161"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update161:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update162"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update162:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update171"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update171:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update172"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update172:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update181"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update181:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update191"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update191:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update192"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update192:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update201"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update201:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update202"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update202:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update211"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update211:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update212"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update212:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update221"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update221:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update222"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update222:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update231"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update231:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update232"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update232:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update241"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update241:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update242"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update242:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update252"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update252:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update262"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update262:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update271"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update271:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update281"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update281:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update282"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update282:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update291"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update291:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8-update292"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:8:update292:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "9.0"
}
],
"cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
}
]
}{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "20.3.2"
},
{
"last_affected": "21.1.0"
}
],
"cpe": [
"cpe:2.3:a:oracle:graalvm:20.3.2:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:oracle:graalvm:21.1.0:*:*:*:enterprise:*:*:*"
]
}{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "16"
}
],
"cpe": "cpe:2.3:a:oracle:openjdk:16:*:*:*:*:*:*:*"
}{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "8-update101"
},
{
"last_affected": "8-update102"
},
{
"last_affected": "8-update11"
},
{
"last_affected": "8-update111"
},
{
"last_affected": "8-update112"
},
{
"last_affected": "8-update20"
},
{
"last_affected": "8-update25"
},
{
"last_affected": "11"
},
{
"last_affected": "13"
},
{
"last_affected": "15"
},
{
"last_affected": "15.0.1"
},
{
"last_affected": "15.0.2"
},
{
"last_affected": "15.0.3"
},
{
"last_affected": "10.0"
}
],
"cpe": [
"cpe:2.3:a:oracle:openjdk:8:update101:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update102:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update11:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update111:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update112:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update20:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update25:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:11:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:13:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:15:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:15.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:15.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:15.0.3:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"
]
}{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "8-update121"
},
{
"last_affected": "8-update131"
}
],
"cpe": [
"cpe:2.3:a:oracle:openjdk:8:update121:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update131:*:*:*:*:*:*"
]
}