CVE-2022-21628
Published Oct 18, 2022
·Updated
Java SE is vulnerable to a denial of service, caused by a flaw in the Lightweight HTTP Server. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Affected Software
35 affected componentsFixes available
Oracle GraalVM=20.3.7
Oracle GraalVM=21.3.3
Oracle GraalVM=22.2.0
Oracle JDK=1.8.0-update341
Oracle JDK=1.8.0-update345
Oracle JDK=11.0.16.1
Oracle JDK=17.0.4.1
Oracle JDK=19
Oracle JRE=1.8.0-update341
Oracle JRE=1.8.0-update345
Oracle JRE=11.0.16.1
Oracle JRE=17.0.4.1
Oracle JRE=19
Fedoraproject Fedora=35
Fedoraproject Fedora=36
NetApp 7-Mode Transition Tool
NetApp Cloud Insights Acquisition Unit
NetApp Cloud Secure Agent
NetApp E-Series SANtricity OS Controller>=11.0<=11.70.2
NetApp E-series Santricity Storage Manager
NetApp E-series Santricity Unified Manager
NetApp OnCommand Insight
NetApp OnCommand Workflow Automation
NetApp Santricity Storage Plugin Vcenter
NetApp SANtricity Web Services Proxy
Azul Zulu=6.49
Azul Zulu=7.56
Azul Zulu=8.64
Azul Zulu=11.58
Azul Zulu=13.50
Azul Zulu=15.42
Azul Zulu=17.36
Azul Zulu=19.28
Microsoft cm1 openjdk8 1.8.0.332-2
IBM DB2 Recovery Expert for LUW<=5.5 IF 2
Remediation
Patch Available
Event History
Oct 18, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Oct 1, 2025
Data Sourced
via Microsoft·11:11 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·11:11 PM
Affected Software
Updated
via Microsoft·11:11 PM
DescriptionSeverity
Feb 5, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2022-21628?
CVE-2022-21628 is a vulnerability in the Lightweight HTTP Server component of Oracle Java SE and Oracle GraalVM Enterprise Edition.
2
What is the severity of CVE-2022-21628?
The severity of CVE-2022-21628 is medium with a CVSS score of 5.3.
3
Which versions of Oracle Java SE are affected by CVE-2022-21628?
The affected versions of Oracle Java SE are 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, and 19.
4
Which versions of Oracle GraalVM Enterprise Edition are affected by CVE-2022-21628?
The affected versions of Oracle GraalVM Enterprise Edition are 20.3.7, 21.3.3, and 22.2.0.
5
How can I fix CVE-2022-21628?
To fix CVE-2022-21628, update to the patched versions of Oracle Java SE and Oracle GraalVM Enterprise Edition.