Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via Kerberos to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N).
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "11.0.0"
},
{
"last_affected": "11.50.2"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "1.8.0-update301"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:jdk:1.8.0:update301:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "11.0.12"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:jdk:11.0.12:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "1.8.0-update301"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:jre:1.8.0:update301:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "11.0.12"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:jre:11.0.12:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "11.0.10"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.10:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "11.0.11"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.11:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "11.0.12"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.12:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "11.0.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.1:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "11.0.2"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.2:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "11.0.3"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.3:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "11.0.4"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.4:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "11.0.5"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.5:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "11.0.6"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.6:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "11.0.7"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.7:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "11.0.8"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.8:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "11.0.9"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:11.0.9:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "13.0.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:13.0.1:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "13.0.2"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:13.0.2:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "13.0.3"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:13.0.3:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "13.0.4"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:13.0.4:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "13.0.5"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:13.0.5:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "13.0.6"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:13.0.6:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "13.0.7"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:13.0.7:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "13.0.8"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:13.0.8:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "16.0.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:16.0.1:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "16.0.2"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:16.0.2:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-NA"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:-:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-milestone1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone1:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-milestone2"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone2:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-milestone3"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone3:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-milestone4"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone4:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-milestone5"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone5:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-milestone6"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone6:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-milestone7"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone7:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-milestone8"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone8:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-milestone9"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:milestone9:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update141"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update141:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update151"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update151:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update152"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update152:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update161"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update161:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update162"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update162:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update171"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update171:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update172"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update172:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update181"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update181:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update191"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update191:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update192"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update192:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update201"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update201:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update202"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update202:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update211"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update211:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update212"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update212:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update221"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update221:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update222"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update222:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update231"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update231:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update232"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update232:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update241"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update241:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update242"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update242:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update252"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update252:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update262"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update262:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update271"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update271:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update281"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update281:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update282"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update282:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update291"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update291:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update292"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update292:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update301"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update301:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8-update302"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:openjdk:8:update302:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "9.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "33"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "34"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "35"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*"
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "20.3.3"
},
{
"last_affected": "21.2.0"
}
],
"source": "CPE_FIELD",
"cpe": [
"cpe:2.3:a:oracle:graalvm:20.3.3:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:oracle:graalvm:21.2.0:*:*:*:enterprise:*:*:*"
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "16"
},
{
"last_affected": "17"
}
],
"source": "CPE_FIELD",
"cpe": [
"cpe:2.3:a:oracle:openjdk:16:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:jdk:17:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:jre:17:*:*:*:*:*:*:*"
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "8-update101"
},
{
"last_affected": "8-update102"
},
{
"last_affected": "8-update11"
},
{
"last_affected": "8-update111"
},
{
"last_affected": "8-update112"
},
{
"last_affected": "8-update20"
},
{
"last_affected": "8-update25"
},
{
"last_affected": "8-update31"
},
{
"last_affected": "11"
},
{
"last_affected": "13"
},
{
"last_affected": "15"
},
{
"last_affected": "15.0.1"
},
{
"last_affected": "15.0.2"
},
{
"last_affected": "15.0.3"
},
{
"last_affected": "15.0.4"
},
{
"last_affected": "10.0"
},
{
"last_affected": "11.0"
}
],
"source": "CPE_FIELD",
"cpe": [
"cpe:2.3:a:oracle:openjdk:8:update101:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update102:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update11:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update111:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update112:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update20:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update25:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update31:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:11:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:13:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:15:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:15.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:15.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:15.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:15.0.4:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*"
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "8-update121"
},
{
"last_affected": "8-update131"
}
],
"source": "CPE_FIELD",
"cpe": [
"cpe:2.3:a:oracle:openjdk:8:update121:*:*:*:*:*:*",
"cpe:2.3:a:oracle:openjdk:8:update131:*:*:*:*:*:*"
]
}