Lucene search

K
redhatRedHatRHSA-2022:8880
HistoryDec 07, 2022 - 10:41 a.m.

(RHSA-2022:8880) Moderate: java-1.8.0-ibm security update

2022-12-0710:41:58
access.redhat.com
21
ibm java se 8
security update
cve-2022-21626
cve-2022-21628
cve-2022-21619
cve-2022-21624
openjdk
x.509 certificate parsing
httpserver
ntlm client hostnames
jndi dns

0.002 Low

EPSS

Percentile

59.6%

IBM Java SE version 8 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit.

This update upgrades IBM Java SE 8 to version 8 SR7-FP20.

Security Fix(es):

  • OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533) (CVE-2022-21626)

  • OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) (CVE-2022-21628)

  • OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) (CVE-2022-21619)

  • OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910) (CVE-2022-21624)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.