CVE-2023-21830
Published Jan 12, 2023
·Updated
An unspecified flaw was found in the way the Serialization component of OpenJDK performed deserialization of data from serialized input. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Affected Software
27 affected componentsFixes available
redhat/java<1.8.0-openjdk-1:1.8.0.362.b08-1.el7_9
1.8.0-openjdk-1:1.8.0.362.b08-1.el7_9
redhat/java<1.8.0-ibm-1:1.8.0.8.0-1jpp.1.el7
1.8.0-ibm-1:1.8.0.8.0-1jpp.1.el7
redhat/java<1.8.0-openjdk-1:1.8.0.362.b09-2.el8_7
1.8.0-openjdk-1:1.8.0.362.b09-2.el8_7
redhat/java<1.8.0-openjdk-1:1.8.0.362.b08-1.el8_1
1.8.0-openjdk-1:1.8.0.362.b08-1.el8_1
redhat/java<1.8.0-openjdk-1:1.8.0.362.b08-1.el8_2
1.8.0-openjdk-1:1.8.0.362.b08-1.el8_2
redhat/java<1.8.0-openjdk-1:1.8.0.362.b08-1.el8_4
1.8.0-openjdk-1:1.8.0.362.b08-1.el8_4
redhat/java<1.8.0-openjdk-1:1.8.0.362.b08-1.el8_6
1.8.0-openjdk-1:1.8.0.362.b08-1.el8_6
redhat/java<1.8.0-openjdk-1:1.8.0.362.b09-2.el9_1
1.8.0-openjdk-1:1.8.0.362.b09-2.el9_1
redhat/java<1.8.0-openjdk-1:1.8.0.362.b08-2.el9_0
1.8.0-openjdk-1:1.8.0.362.b08-2.el9_0
Oracle Communications Unified Assurance>=5.5.0<=5.5.17
Oracle Communications Unified Assurance>=6.0.0<=6.0.2
Oracle GraalVM=20.3.8
Oracle GraalVM=21.3.4
Oracle GraalVM=22.3.0
Oracle JDK=1.8.0-update351
Oracle JDK=11.0.17
Oracle JDK=17.0.5
Oracle JDK=19.0.1
Oracle JRE=1.8.0-update351
Oracle JRE=11.0.17
Oracle JRE=17.0.5
Oracle JRE=19.0.1
Azul Zulu=6.51
Azul Zulu=7.57
Azul Zulu=8.66
Microsoft cm1 openjdk8 1.8.0.332-2
IBM InfoSphere Data Architect<=9.2.1
Remediation
Patch Available
Patch Available
Event History
Jan 12, 2023
Data Sourced
via Red Hat·03:16 PM
DescriptionSeverityAffected Software
Jan 17, 2023
CVE Published
08:00 PM
CVE Published
via MITRE·11:35 PM
Data Sourced
via MITRE·11:35 PM
DescriptionSeverity
Oct 1, 2025
Data Sourced
via Microsoft·11:11 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·11:11 PM
Affected Software
Updated
via Microsoft·11:11 PM
DescriptionSeverity
Mar 4, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-21830.
2
Which component of Java SE is affected by this vulnerability?
This vulnerability affects the Serialization component of Java SE.
3
What is the severity of CVE-2023-21830?
The severity of CVE-2023-21830 is medium with a CVSS score of 5.3.
4
Which versions of Oracle Java SE and GraalVM Enterprise Edition are affected by this vulnerability?
The affected versions are Oracle Java SE: 8u351, 8u351-perf; Oracle GraalVM Enterprise Edition: 20.3.8 and 21.3.4.
5
How can I fix CVE-2023-21830?
To fix this vulnerability, update your Oracle Java SE or GraalVM Enterprise Edition to the recommended versions provided by Oracle.