CVE-2022-21476: High severity Oracle GraalVM vulnerability
A flaw was found in Apache Santuario (XML Security for Java) in the way it processed some paths. A remote attacker could use this flaw to circumvent the "secure validation" feature and disclose potentially sensitive information in local XML files.
Other sources
An unspecified vulnerability in Java SE related to the Libraries component could allow an unauthenticated attacker to obtain sensitive information resulting in a high confidentiality impact using unknown attack vectors.
— IBM
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this Oracle Java SE vulnerability?
The vulnerability ID is CVE-2022-21476.
What is the affected software?
The affected software includes Oracle Java SE versions 7u331, 8u321, 11.0.14, 17.0.2, and 18, as well as Oracle GraalVM Enterprise Edition versions 20.3.5, 21.3.1, and 22.0.0.2.
How severe is the vulnerability?
The vulnerability has a severity rating of 7.5 (high).
What is the Common Weakness Enumeration (CWE) ID associated with this vulnerability?
The CWE ID associated with this vulnerability is CWE-179.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Red Hat errata pages: [RHSA-2022:1443](https://access.redhat.com/errata/RHSA-2022:1443), [RHSA-2022:1444](https://access.redhat.com/errata/RHSA-2022:1444), [RHSA-2022:1441](https://access.redhat.com/errata/RHSA-2022:1441).