CVE-2023-21843
An unspecified vulnerability in Java SE related to the Sound component could allow a remote attacker to cause a denial of service resulting in a low integrity impact using unknown attack vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-21843?
CVE-2023-21843 is an unspecified vulnerability in Java SE related to the Sound component that could allow a remote attacker to... (answer continued)
What versions of Oracle Java SE are affected by CVE-2023-21843?
Supported versions that are affected are Oracle Java SE: 8u351, 8u351-perf, 11.0.17, 17.0.5, 19.0.1.
What versions of Oracle GraalVM Enterprise Edition are affected by CVE-2023-21843?
Supported versions that are affected are Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and 22.3.0.
What is the severity of CVE-2023-21843?
The severity of CVE-2023-21843 is low, with a severity value of 3.7.
How can I fix CVE-2023-21843?
To fix CVE-2023-21843, update to the latest version of Oracle Java SE or Oracle GraalVM Enterprise Edition as recommended by the vendor.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-21843?
The CWE ID for CVE-2023-21843 is CWE-646.
Where can I find more information about CVE-2023-21843?
More information about CVE-2023-21843 can be found at the following references: [Link 1](https://github.com/openjdk/jdk17u/commit/45650552132297f296648ffccaa9668888c6707d), [Link 2](https://github.com/openjdk/jdk11u/commit/b46279bb15ab187e60c71b400e4363548969445a), [Link 3](https://github.com/openjdk/jdk8u/commit/00dbe881f5fb7b74c93762ddd06a33a716f786ce).