Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u371, 8u371-perf, 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and 20.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
{
    "binaries": [
        {
            "binary_version": "9~b114-0ubuntu1",
            "binary_name": "openjdk-9-demo"
        },
        {
            "binary_version": "9~b114-0ubuntu1",
            "binary_name": "openjdk-9-jdk"
        },
        {
            "binary_version": "9~b114-0ubuntu1",
            "binary_name": "openjdk-9-jdk-headless"
        },
        {
            "binary_version": "9~b114-0ubuntu1",
            "binary_name": "openjdk-9-jre"
        },
        {
            "binary_version": "9~b114-0ubuntu1",
            "binary_name": "openjdk-9-jre-headless"
        },
        {
            "binary_version": "9~b114-0ubuntu1",
            "binary_name": "openjdk-9-source"
        }
    ]
}{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "17.0.8+7-1~20.04.2",
            "binary_name": "openjdk-17-demo"
        },
        {
            "binary_version": "17.0.8+7-1~20.04.2",
            "binary_name": "openjdk-17-jdk"
        },
        {
            "binary_version": "17.0.8+7-1~20.04.2",
            "binary_name": "openjdk-17-jdk-headless"
        },
        {
            "binary_version": "17.0.8+7-1~20.04.2",
            "binary_name": "openjdk-17-jre"
        },
        {
            "binary_version": "17.0.8+7-1~20.04.2",
            "binary_name": "openjdk-17-jre-headless"
        },
        {
            "binary_version": "17.0.8+7-1~20.04.2",
            "binary_name": "openjdk-17-jre-zero"
        },
        {
            "binary_version": "17.0.8+7-1~20.04.2",
            "binary_name": "openjdk-17-source"
        }
    ]
}{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "8u382-ga-1~20.04.1",
            "binary_name": "openjdk-8-demo"
        },
        {
            "binary_version": "8u382-ga-1~20.04.1",
            "binary_name": "openjdk-8-jdk"
        },
        {
            "binary_version": "8u382-ga-1~20.04.1",
            "binary_name": "openjdk-8-jdk-headless"
        },
        {
            "binary_version": "8u382-ga-1~20.04.1",
            "binary_name": "openjdk-8-jre"
        },
        {
            "binary_version": "8u382-ga-1~20.04.1",
            "binary_name": "openjdk-8-jre-headless"
        },
        {
            "binary_version": "8u382-ga-1~20.04.1",
            "binary_name": "openjdk-8-jre-zero"
        },
        {
            "binary_version": "8u382-ga-1~20.04.1",
            "binary_name": "openjdk-8-source"
        }
    ]
}{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "11.0.20+8-1ubuntu1~20.04",
            "binary_name": "openjdk-11-demo"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~20.04",
            "binary_name": "openjdk-11-jdk"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~20.04",
            "binary_name": "openjdk-11-jdk-headless"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~20.04",
            "binary_name": "openjdk-11-jre"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~20.04",
            "binary_name": "openjdk-11-jre-headless"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~20.04",
            "binary_name": "openjdk-11-jre-zero"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~20.04",
            "binary_name": "openjdk-11-source"
        }
    ]
}{
    "binaries": [
        {
            "binary_version": "13.0.7+5-0ubuntu1~20.04",
            "binary_name": "openjdk-13-demo"
        },
        {
            "binary_version": "13.0.7+5-0ubuntu1~20.04",
            "binary_name": "openjdk-13-jdk"
        },
        {
            "binary_version": "13.0.7+5-0ubuntu1~20.04",
            "binary_name": "openjdk-13-jdk-headless"
        },
        {
            "binary_version": "13.0.7+5-0ubuntu1~20.04",
            "binary_name": "openjdk-13-jre"
        },
        {
            "binary_version": "13.0.7+5-0ubuntu1~20.04",
            "binary_name": "openjdk-13-jre-headless"
        },
        {
            "binary_version": "13.0.7+5-0ubuntu1~20.04",
            "binary_name": "openjdk-13-jre-zero"
        },
        {
            "binary_version": "13.0.7+5-0ubuntu1~20.04",
            "binary_name": "openjdk-13-source"
        }
    ]
}{
    "binaries": [
        {
            "binary_version": "16.0.1+9-1~20.04",
            "binary_name": "openjdk-16-demo"
        },
        {
            "binary_version": "16.0.1+9-1~20.04",
            "binary_name": "openjdk-16-jdk"
        },
        {
            "binary_version": "16.0.1+9-1~20.04",
            "binary_name": "openjdk-16-jdk-headless"
        },
        {
            "binary_version": "16.0.1+9-1~20.04",
            "binary_name": "openjdk-16-jre"
        },
        {
            "binary_version": "16.0.1+9-1~20.04",
            "binary_name": "openjdk-16-jre-headless"
        },
        {
            "binary_version": "16.0.1+9-1~20.04",
            "binary_name": "openjdk-16-jre-zero"
        },
        {
            "binary_version": "16.0.1+9-1~20.04",
            "binary_name": "openjdk-16-source"
        }
    ]
}{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "17.0.8+7-1~22.04",
            "binary_name": "openjdk-17-demo"
        },
        {
            "binary_version": "17.0.8+7-1~22.04",
            "binary_name": "openjdk-17-jdk"
        },
        {
            "binary_version": "17.0.8+7-1~22.04",
            "binary_name": "openjdk-17-jdk-headless"
        },
        {
            "binary_version": "17.0.8+7-1~22.04",
            "binary_name": "openjdk-17-jre"
        },
        {
            "binary_version": "17.0.8+7-1~22.04",
            "binary_name": "openjdk-17-jre-headless"
        },
        {
            "binary_version": "17.0.8+7-1~22.04",
            "binary_name": "openjdk-17-jre-zero"
        },
        {
            "binary_version": "17.0.8+7-1~22.04",
            "binary_name": "openjdk-17-source"
        }
    ]
}{
    "binaries": [
        {
            "binary_version": "18.0.2+9-2~22.04",
            "binary_name": "openjdk-18-demo"
        },
        {
            "binary_version": "18.0.2+9-2~22.04",
            "binary_name": "openjdk-18-jdk"
        },
        {
            "binary_version": "18.0.2+9-2~22.04",
            "binary_name": "openjdk-18-jdk-headless"
        },
        {
            "binary_version": "18.0.2+9-2~22.04",
            "binary_name": "openjdk-18-jre"
        },
        {
            "binary_version": "18.0.2+9-2~22.04",
            "binary_name": "openjdk-18-jre-headless"
        },
        {
            "binary_version": "18.0.2+9-2~22.04",
            "binary_name": "openjdk-18-jre-zero"
        },
        {
            "binary_version": "18.0.2+9-2~22.04",
            "binary_name": "openjdk-18-source"
        }
    ]
}{
    "binaries": [
        {
            "binary_version": "19.0.2+7-0ubuntu3~22.04",
            "binary_name": "openjdk-19-demo"
        },
        {
            "binary_version": "19.0.2+7-0ubuntu3~22.04",
            "binary_name": "openjdk-19-jdk"
        },
        {
            "binary_version": "19.0.2+7-0ubuntu3~22.04",
            "binary_name": "openjdk-19-jdk-headless"
        },
        {
            "binary_version": "19.0.2+7-0ubuntu3~22.04",
            "binary_name": "openjdk-19-jre"
        },
        {
            "binary_version": "19.0.2+7-0ubuntu3~22.04",
            "binary_name": "openjdk-19-jre-headless"
        },
        {
            "binary_version": "19.0.2+7-0ubuntu3~22.04",
            "binary_name": "openjdk-19-jre-zero"
        },
        {
            "binary_version": "19.0.2+7-0ubuntu3~22.04",
            "binary_name": "openjdk-19-source"
        }
    ]
}{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "8u382-ga-1~22.04.1",
            "binary_name": "openjdk-8-demo"
        },
        {
            "binary_version": "8u382-ga-1~22.04.1",
            "binary_name": "openjdk-8-jdk"
        },
        {
            "binary_version": "8u382-ga-1~22.04.1",
            "binary_name": "openjdk-8-jdk-headless"
        },
        {
            "binary_version": "8u382-ga-1~22.04.1",
            "binary_name": "openjdk-8-jre"
        },
        {
            "binary_version": "8u382-ga-1~22.04.1",
            "binary_name": "openjdk-8-jre-headless"
        },
        {
            "binary_version": "8u382-ga-1~22.04.1",
            "binary_name": "openjdk-8-jre-zero"
        },
        {
            "binary_version": "8u382-ga-1~22.04.1",
            "binary_name": "openjdk-8-source"
        }
    ]
}{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "11.0.20+8-1ubuntu1~22.04",
            "binary_name": "openjdk-11-demo"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~22.04",
            "binary_name": "openjdk-11-jdk"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~22.04",
            "binary_name": "openjdk-11-jdk-headless"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~22.04",
            "binary_name": "openjdk-11-jre"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~22.04",
            "binary_name": "openjdk-11-jre-headless"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~22.04",
            "binary_name": "openjdk-11-jre-zero"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~22.04",
            "binary_name": "openjdk-11-source"
        }
    ]
}{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "8u382-ga-1~16.04.1",
            "binary_name": "openjdk-8-demo"
        },
        {
            "binary_version": "8u382-ga-1~16.04.1",
            "binary_name": "openjdk-8-jdk"
        },
        {
            "binary_version": "8u382-ga-1~16.04.1",
            "binary_name": "openjdk-8-jdk-headless"
        },
        {
            "binary_version": "8u382-ga-1~16.04.1",
            "binary_name": "openjdk-8-jre"
        },
        {
            "binary_version": "8u382-ga-1~16.04.1",
            "binary_name": "openjdk-8-jre-headless"
        },
        {
            "binary_version": "8u382-ga-1~16.04.1",
            "binary_name": "openjdk-8-jre-jamvm"
        },
        {
            "binary_version": "8u382-ga-1~16.04.1",
            "binary_name": "openjdk-8-jre-zero"
        },
        {
            "binary_version": "8u382-ga-1~16.04.1",
            "binary_name": "openjdk-8-source"
        }
    ]
}{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "11.0.20+8-1ubuntu1~18.04",
            "binary_name": "openjdk-11-demo"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~18.04",
            "binary_name": "openjdk-11-jdk"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~18.04",
            "binary_name": "openjdk-11-jdk-headless"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~18.04",
            "binary_name": "openjdk-11-jre"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~18.04",
            "binary_name": "openjdk-11-jre-headless"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~18.04",
            "binary_name": "openjdk-11-jre-zero"
        },
        {
            "binary_version": "11.0.20+8-1ubuntu1~18.04",
            "binary_name": "openjdk-11-source"
        }
    ]
}{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "17.0.8+7-1~18.04",
            "binary_name": "openjdk-17-demo"
        },
        {
            "binary_version": "17.0.8+7-1~18.04",
            "binary_name": "openjdk-17-jdk"
        },
        {
            "binary_version": "17.0.8+7-1~18.04",
            "binary_name": "openjdk-17-jdk-headless"
        },
        {
            "binary_version": "17.0.8+7-1~18.04",
            "binary_name": "openjdk-17-jre"
        },
        {
            "binary_version": "17.0.8+7-1~18.04",
            "binary_name": "openjdk-17-jre-headless"
        },
        {
            "binary_version": "17.0.8+7-1~18.04",
            "binary_name": "openjdk-17-jre-zero"
        },
        {
            "binary_version": "17.0.8+7-1~18.04",
            "binary_name": "openjdk-17-source"
        }
    ]
}{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "8u382-ga-1~18.04.1",
            "binary_name": "openjdk-8-demo"
        },
        {
            "binary_version": "8u382-ga-1~18.04.1",
            "binary_name": "openjdk-8-jdk"
        },
        {
            "binary_version": "8u382-ga-1~18.04.1",
            "binary_name": "openjdk-8-jdk-headless"
        },
        {
            "binary_version": "8u382-ga-1~18.04.1",
            "binary_name": "openjdk-8-jre"
        },
        {
            "binary_version": "8u382-ga-1~18.04.1",
            "binary_name": "openjdk-8-jre-headless"
        },
        {
            "binary_version": "8u382-ga-1~18.04.1",
            "binary_name": "openjdk-8-jre-zero"
        },
        {
            "binary_version": "8u382-ga-1~18.04.1",
            "binary_name": "openjdk-8-source"
        }
    ]
}