[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2021-35565Date: (C)2021-10-20   (M)2024-03-22


Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 5.3CVSS Score : 5.0
Exploit Score: 3.9Exploit Score: 10.0
Impact Score: 1.4Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: NONE
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: NONEAvailability: PARTIAL
Integrity: NONE 
Availability: LOW 
  
Reference:
DSA-5000
FEDORA-2021-107c8c5063
FEDORA-2021-1cc8ffd122
FEDORA-2021-35145352b0
FEDORA-2021-7701833090
FEDORA-2021-9a51a6f8b1
FEDORA-2021-eb3e3e87d3
GLSA-202209-05
https://lists.debian.org/debian-lts-announce/2021/11/msg00008.html
https://security.netapp.com/advisory/ntap-20211022-0004/
https://www.oracle.com/security-alerts/cpuoct2021.html

CPE    1
cpe:/o:debian:debian_linux:9.0
OVAL    50
oval:org.secpod.oval:def:2500407
oval:org.secpod.oval:def:75502
oval:org.secpod.oval:def:75501
oval:org.secpod.oval:def:89045938
...

© SecPod Technologies