Improper input validation in Oracle GraalVM Enterprise Edition - CVE-2026-21945
Published: January 20, 2026
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Security component in Oracle GraalVM Enterprise Edition. A remote non-authenticated attacker can exploit this vulnerability to perform a denial of service (DoS) attack.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
Debian Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Anolis OS
IBM i
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Basesystem Module
Legacy Module
SUSE Package Hub 15
openSUSE Leap
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
Ubuntu
WebSphere Service Registry and Repository
SecurID Governance and Lifecycle
IBM Sterling Connect:Direct FTP+
IBM Content Collector for SAP Applications
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Match 360
IBM Sterling Control Center
Communications Server for Linux on System z
Communications Server for Data Center Deployment
IBM Tivoli Netcool Impact
IBM Tivoli Netcool/OMNIbus WebGUI
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM SPSS Collaboration and Deployment Services
WebSphere eXtreme Scale
IBM Common Licensing
IBM Rational ClearCase
IBM Transformation Extender Advanced
IBM Sterling Transformation Extender
IBM SPSS Modeler
Oracle Communications Cloud Native Core Certificate Management
IBM Tivoli System Automation Application Manager
IBM Sterling Connect:Direct for UNIX
IBM MQ
IBM Power Hardware Management Console (HMC)
Red Hat build of Keycloak
SPSS Statistics
RSA Identity Governance and Lifecycle
B2B Advanced Communications
Storage Defender - Resiliency Service
DataStage on Cloud Pak for Data
Communications Server for Linux
Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines
Tivoli Monitoring for Virtual Environments Base
Storage Protect Server
Storage Protect Operations Center
IBM OpenPages with Watson
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
IBM MQ Appliance
IBM Security Verify Directory
IBM Engineering Systems Design Rhapsody
DevOps Code ClearCase
Integration Designer
PowerVM NovaLink
Tivoli System Automation for Multiplatforms
IBM Sterling Connect:Direct for Microsoft Windows
Tivoli Composite Application Manager for Applications WebSphere MQ Monitoring Agent
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Space Management
Guardium Data Protection
Robotic Process Automation for Cloud Pak
Voice Gateway
IBM Sterling Connect:Direct File Agent
IBM DataPower Gateway
IBM Enterprise Content Management System Monitor
IBM Copy Services Manager
Planning Analytics Local
IBM Cloud Pak System
IBM Tivoli Application Dependency Discovery Manager
Oracle Java SE
Rational Business Developer (RBD)
IBM CICS TX Standard
IBM App Connect Enterprise
Oracle GraalVM for JDK
IBM Java SDK
IBM CICS TX Advanced
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
java-1_8_0-ibm
java-1_8_0-ibm-devel
java-1_8_0-ibm-alsa
java-1_8_0-ibm-plugin
java-1_8_0-ibm-32bit
java-1_8_0-ibm-demo
java-1_8_0-ibm-src
java-1_8_0-ibm-devel-32bit
java-1.8.0-ibm-headless (Red Hat package)
java-1.8.0-ibm-jdbc (Red Hat package)
java-1.8.0-ibm (Red Hat package)
java-1.8.0-ibm-plugin (Red Hat package)
java-1.8.0-ibm-src (Red Hat package)
java-1.8.0-ibm-webstart (Red Hat package)
java-1.8.0-ibm-devel (Red Hat package)
java-1.8.0-ibm-demo (Red Hat package)
java-1.8.0-openjdk-src
java-1.8.0-openjdk-javadoc-zip
java-1.8.0-openjdk-javadoc
java-1.8.0-openjdk-headless
java-1.8.0-openjdk-devel
java-1.8.0-openjdk-demo
java-1.8.0-openjdk-accessibility
java-1.8.0-openjdk
java-1.8.0-openjdk-devel-debug
java-1.8.0-openjdk-demo-debug
java-1.8.0-openjdk-debug
java-1.8.0-openjdk-accessibility-debug
java-1.8.0-openjdk-javadoc-zip-debug
java-1.8.0-openjdk-javadoc-debug
java-1.8.0-openjdk-headless-debug
java-1.8.0-openjdk-src-debug
java-1.8.0-openjdk (Red Hat package)
java-1_8_0-openjdk-demo
java-1_8_0-openjdk-headless
java-1_8_0-openjdk-debugsource
java-1_8_0-openjdk-devel-debuginfo
java-1_8_0-openjdk-demo-debuginfo
java-1_8_0-openjdk-debuginfo
java-1_8_0-openjdk-headless-debuginfo
java-1_8_0-openjdk
java-1_8_0-openjdk-devel
java-1_8_0-openjdk-src
java-1_8_0-openjdk-accessibility
java-1_8_0-openjdk-javadoc
java-1_8_0-openj9-debuginfo
java-1_8_0-openj9
java-1_8_0-openj9-demo-debuginfo
java-1_8_0-openj9-accessibility
java-1_8_0-openj9-devel-debuginfo
java-1_8_0-openj9-debugsource
java-1_8_0-openj9-headless
java-1_8_0-openj9-headless-debuginfo
java-1_8_0-openj9-demo
java-1_8_0-openj9-devel
java-1_8_0-openj9-src
java-1_8_0-openj9-javadoc
openjdk-8 (Ubuntu package)
java-11-openjdk
java-11-openjdk-debugsource
java-11-openjdk-headless
java-11-openjdk-devel
java-11-openjdk-demo
java-11-openjdk-debuginfo
java-11-openjdk-src
java-11-openjdk-devel-debuginfo
java-11-openjdk-javadoc
java-11-openjdk-headless-debuginfo
java-11-openjdk-jmods
openjdk-lts (Ubuntu package)
java-17-openjdk-javadoc-zip
java-17-openjdk
java-17-openjdk-demo
java-17-openjdk-devel
java-17-openjdk-headless
java-17-openjdk-javadoc
java-17-openjdk-static-libs
java-17-openjdk-src
java-17-openjdk-jmods
java-17-openjdk (Red Hat package)
java-17-openjdk-debugsource
java-17-openjdk-headless-debuginfo
java-17-openjdk-devel-debuginfo
java-17-openjdk-debuginfo
openjdk-17-crac (Ubuntu package)
openjdk-17 (debian package)
openjdk-17 (Ubuntu package)
java-21-openjdk-javadoc
java-21-openjdk-headless
java-21-openjdk-devel
java-21-openjdk-demo
java-21-openjdk
java-21-openjdk-javadoc-zip
java-21-openjdk-jmods
java-21-openjdk-src
java-21-openjdk-static-libs
java-21-openjdk-debuginfo
java-21-openjdk-devel-debuginfo
java-21-openjdk-debugsource
java-21-openjdk-headless-debuginfo
openjdk-21-crac (Ubuntu package)
openjdk-21 (Debian package)
openjdk-21 (Ubuntu package)
java-25-openjdk-headless-debuginfo
java-25-openjdk-headless
java-25-openjdk-debuginfo
java-25-openjdk-demo
java-25-openjdk
java-25-openjdk-devel-debuginfo
java-25-openjdk-devel
openjdk-25-crac (Ubuntu package)
openjdk-25 (Debian package)
openjdk-25 (Ubuntu package)
IBM Cognos Command Center
IBM InfoSphere Information Server
IBM DB2
Oracle Communications Cloud Native Core Console
IBM WebSphere Application Server
Informix Dynamic Server
How to mitigate CVE-2026-21945
Voice Gateway - addressed in versions 1.0.8.19, 1.0.8.25
IBM Sterling Connect:Direct FTP+ - update to 1.3.0.4
IBM Sterling Connect:Direct File Agent - update to 1.4.0.5 iFix006
Storage Defender - Resiliency Service - update to 2.1.3
Planning Analytics Local - update to 2.1.19
IBM Cloud Pak System - update to 2.3.5.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
DataStage on Cloud Pak for Data - update to 5.3.1 patch 3
IBM Sterling Control Center - addressed in versions 6.3.1.0.7, 6.4.1.0.1, 6.4.2.0.1
IBM Tivoli Netcool Impact - update to 7.1.0.38
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
Storage Protect Server - update to 8.2.1
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix16
Storage Protect Operations Center - update to 8.2.1
WebSphere eXtreme Scale - update to 8.6.1.6 PH70422
IBM MQ Appliance - addressed in versions 9.4.0.20, 9.4.5.1
Rational Business Developer (RBD) - addressed in versions 9.6.1.1, 9.7.1
IBM Security Verify Directory - update to 11.0.0.1
IBM Engineering Systems Design Rhapsody - addressed in versions 10.0.0.5, 10.0.1.0.5, 10.0.2.0.4
IBM Transformation Extender Advanced - addressed in versions 10.0.1.11 1iFix, 10.0.2.1 1iFix
IBM Cognos Command Center - update to 10.2.5 FP1 IF3
IBM DataPower Gateway - addressed in versions 10.5.0.21, 10.6.0.9, 11.0.0.0
IBM CICS TX Standard - update to 11.1.0.0 ifix39
IBM App Connect Enterprise - addressed in versions 12.0.12.23, 13.0.6.2
java-1_8_0-ibm - addressed in versions 1.8.0_sr8.60-30.146.1, 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr8.60-30.146.1, 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr8.60-30.146.1, 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr8.60-30.146.1, 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-32bit - update to 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-demo - update to 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-src - update to 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-devel-32bit - update to 1.8.0_sr8.60-150000.3.112.1
java-1.8.0-ibm-headless (Red Hat package) - update to 1.8.0.8.60-1.el8_10
java-1.8.0-ibm-jdbc (Red Hat package) - update to 1.8.0.8.60-1.el8_10
java-1.8.0-ibm (Red Hat package) - update to 1.8.0.8.60-1.el8_10
java-1.8.0-ibm-plugin (Red Hat package) - update to 1.8.0.8.60-1.el8_10
java-1.8.0-ibm-src (Red Hat package) - update to 1.8.0.8.60-1.el8_10
java-1.8.0-ibm-webstart (Red Hat package) - update to 1.8.0.8.60-1.el8_10
java-1.8.0-ibm-devel (Red Hat package) - update to 1.8.0.8.60-1.el8_10
java-1.8.0-ibm-demo (Red Hat package) - update to 1.8.0.8.60-1.el8_10
java-1.8.0-openjdk-src - addressed in versions 1.8.0.482.b08-1.0.1, 1.8.0.482.b08-1
java-1.8.0-openjdk-javadoc-zip - addressed in versions 1.8.0.482.b08-1.0.1, 1.8.0.482.b08-1
java-1.8.0-openjdk-javadoc - addressed in versions 1.8.0.482.b08-1.0.1, 1.8.0.482.b08-1
java-1.8.0-openjdk-headless - addressed in versions 1.8.0.482.b08-1.0.1, 1.8.0.482.b08-1
java-1.8.0-openjdk-devel - addressed in versions 1.8.0.482.b08-1.0.1, 1.8.0.482.b08-1
java-1.8.0-openjdk-demo - addressed in versions 1.8.0.482.b08-1.0.1, 1.8.0.482.b08-1
java-1.8.0-openjdk-accessibility - addressed in versions 1.8.0.482.b08-1.0.1, 1.8.0.482.b08-1
java-1.8.0-openjdk - addressed in versions 1.8.0.482.b08-1.0.1, 1.8.0.482.b08-1
java-1.8.0-openjdk-devel-debug - update to 1.8.0.482.b08-1
java-1.8.0-openjdk-demo-debug - update to 1.8.0.482.b08-1
java-1.8.0-openjdk-debug - update to 1.8.0.482.b08-1
java-1.8.0-openjdk-accessibility-debug - update to 1.8.0.482.b08-1
java-1.8.0-openjdk-javadoc-zip-debug - update to 1.8.0.482.b08-1
java-1.8.0-openjdk-javadoc-debug - update to 1.8.0.482.b08-1
java-1.8.0-openjdk-headless-debug - update to 1.8.0.482.b08-1
java-1.8.0-openjdk-src-debug - update to 1.8.0.482.b08-1
java-1.8.0-openjdk (Red Hat package) - update to 1.8.0.482.b08-1.el7_9
java-1_8_0-openjdk-demo - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-headless - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-debugsource - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-devel-debuginfo - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-demo-debuginfo - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-debuginfo - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-headless-debuginfo - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-devel - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-src - update to 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-accessibility - update to 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-javadoc - update to 1.8.0.482-150000.3.117.1
java-1_8_0-openj9-debuginfo - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9 - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-demo-debuginfo - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-accessibility - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-devel-debuginfo - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-debugsource - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-headless - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-headless-debuginfo - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-demo - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-devel - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-src - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-javadoc - update to 1.8.0.482-150200.3.63.1
PowerVM NovaLink - addressed in versions 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422
IBM Tivoli System Automation Application Manager - addressed in versions 4.1.0.3.0.18, 4.1.0.4.0.15, 4.1.0.5.0.13, 4.1.0.6.0.7, 4.1.0.7.0.2
Tivoli System Automation for Multiplatforms - addressed in versions 4.1.0.4.0.26, 4.1.0.5.0.20, 4.1.0.6.0.15, 4.1.0.7.0.15, 4.1.1.0.0.9, 4.1.1.1.0.10
IBM Enterprise Content Management System Monitor - update to 5.7.000 FP2
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.3.0.6.iFix033, 6.4.0.4.iFix017
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.3.0.6.39, 6.4.0.4.10
IBM Copy Services Manager - update to 6.3.17
IBM Java SDK - addressed in versions 7.1.5.29, 8.0.8.60
Tivoli Composite Application Manager for Applications WebSphere MQ Monitoring Agent - update to 7.3.0 Fix Pack 4
openjdk-8 (Ubuntu package) - addressed in versions 8u482-ga~us1-0ubuntu1~16.04, 8u482-ga~us1-0ubuntu1~18.04, 8u482-ga~us1-0ubuntu1~20.04, 8u482-ga~us1-0ubuntu1~22.04, 8u482-ga~us1-0ubuntu1~24.04, 8u482-ga~us1-0ubuntu1~25.10
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
Storage Protect Client - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
IBM WebSphere Application Server - update to 8.5.5.29
IBM MQ - addressed in versions 9.1.0.36, 9.2.0.42, 9.3.0.40, 9.4.5.1
IBM CICS TX Advanced - update to 10.1.0.0 ifix46
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1063.2, 11.1.1111.5
java-11-openjdk - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk-debugsource - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk-headless - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk-devel - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk-demo - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk-debuginfo - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk-src - update to 11.0.30.0-150000.3.135.1
java-11-openjdk-devel-debuginfo - update to 11.0.30.0-150000.3.135.1
java-11-openjdk-javadoc - update to 11.0.30.0-150000.3.135.1
java-11-openjdk-headless-debuginfo - update to 11.0.30.0-150000.3.135.1
java-11-openjdk-jmods - update to 11.0.30.0-150000.3.135.1
openjdk-lts (Ubuntu package) - addressed in versions 11.0.30+7-1ubuntu1~18.04, 11.0.30+7-1ubuntu1~20.04, 11.0.30+7-1ubuntu1~22.04, 11.0.30+7-1ubuntu1~24.04, 11.0.30+7-1ubuntu1~25.10
Guardium Data Protection - addressed in versions 12.0p140, 12.2.1
Informix Dynamic Server - update to 12.10.xC16W6
java-17-openjdk-javadoc-zip - addressed in versions 17.0.18.0.8-1, 17.0.18.0.8-1.0.2
java-17-openjdk - addressed in versions 17.0.18.0.8-1, 17.0.18.0.8-1.0.2
java-17-openjdk-demo - addressed in versions 17.0.18.0.8-1, 17.0.18.0.8-1.0.2
java-17-openjdk-devel - addressed in versions 17.0.18.0.8-1, 17.0.18.0.8-1.0.2
java-17-openjdk-headless - addressed in versions 17.0.18.0.8-1, 17.0.18.0.8-1.0.2
java-17-openjdk-javadoc - addressed in versions 17.0.18.0.8-1, 17.0.18.0.8-1.0.2
java-17-openjdk-static-libs - addressed in versions 17.0.18.0.8-1, 17.0.18.0.8-1.0.2
java-17-openjdk-src - addressed in versions 17.0.18.0.8-1, 17.0.18.0.8-1.0.2
java-17-openjdk-jmods - addressed in versions 17.0.18.0.8-1, 17.0.18.0.8-1.0.2
java-17-openjdk (Red Hat package) - addressed in versions 17.0.18.0.8-1.el8, 17.0.18.0.8-1.el9
java-17-openjdk-src - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-devel - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-javadoc - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-debugsource - update to 17.0.18.0-150400.3.63.1
java-17-openjdk-headless-debuginfo - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-headless - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-demo - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-devel-debuginfo - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-jmods - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-debuginfo - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
openjdk-17-crac (Ubuntu package) - update to 17.0.18+8-0ubuntu1~25.10
openjdk-17 (debian package) - update to 17.0.18+8-1~deb12u1
openjdk-17 (Ubuntu package) - addressed in versions 17.0.18+8-1~18.04, 17.0.18+8-1~20.04, 17.0.18+8-1~22.04.1, 17.0.18+8-1~24.04.1, 17.0.18+8-1~25.10.1
java-21-openjdk-javadoc - update to 21.0.10.0.7-1.0.2
java-21-openjdk-headless - update to 21.0.10.0.7-1.0.2
java-21-openjdk-devel - update to 21.0.10.0.7-1.0.2
java-21-openjdk-demo - update to 21.0.10.0.7-1.0.2
java-21-openjdk - update to 21.0.10.0.7-1.0.2
java-21-openjdk-javadoc-zip - update to 21.0.10.0.7-1.0.2
java-21-openjdk-jmods - update to 21.0.10.0.7-1.0.2
java-21-openjdk-src - update to 21.0.10.0.7-1.0.2
java-21-openjdk-static-libs - update to 21.0.10.0.7-1.0.2
java-21-openjdk-debuginfo - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-devel-debuginfo - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-javadoc - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-debugsource - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-jmods - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-headless - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-devel - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-headless-debuginfo - update to 21.0.10.0-150600.3.23.1
java-21-openjdk - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-src - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-demo - update to 21.0.10.0-150600.3.23.1
openjdk-21-crac (Ubuntu package) - update to 21.0.10+7-0ubuntu1~25.10
openjdk-21 (Debian package) - update to 21.0.10+7-1~deb13u1
openjdk-21 (Ubuntu package) - addressed in versions 21.0.10+7-1~20.04, 21.0.10+7-1~22.04, 21.0.10+7-1~24.04, 21.0.10+7-1~25.10
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.6, 30.0.2
java-25-openjdk-headless-debuginfo - update to 25.0.2.0-150700.15.7.1
java-25-openjdk-headless - update to 25.0.2.0-150700.15.7.1
java-25-openjdk-debuginfo - update to 25.0.2.0-150700.15.7.1
java-25-openjdk-demo - update to 25.0.2.0-150700.15.7.1
java-25-openjdk - update to 25.0.2.0-150700.15.7.1
java-25-openjdk-devel-debuginfo - update to 25.0.2.0-150700.15.7.1
java-25-openjdk-devel - update to 25.0.2.0-150700.15.7.1
openjdk-25-crac (Ubuntu package) - update to 25.0.2+10-0ubuntu1~25.10
openjdk-25 (Debian package) - update to 25.0.2+10-1~deb13u2
openjdk-25 (Ubuntu package) - addressed in versions 25.0.2+10-1~22.04, 25.0.2+10-1~24.04, 25.0.2+10-1~25.10
Red Hat build of Keycloak - update to 26.2.13
SPSS Statistics - addressed in versions 28.0.1.1 IF017, 29.0.2.0 IF018, 30.0.0.0 IF014, 31.0.2.0 IF06
External References
Related Security Bulletins
- Multiple vulnerabilities in Oracle GraalVM Enterprise Edition
- Multiple vulnerabilities in Oracle Java SE
- Multiple vulnerabilities in Oracle GraalVM for JDK
- Red Hat Enterprise Linux 9 update for java-17-openjdk
- Debian update for openjdk-17
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for java-1.8.0-openjdk
- Multiple vulnerabilities in IBM SDK, Java Technology Edition
- Debian update for openjdk-21
- Multiple vulnerabilities in IBM WebSphere Application Server
- SUSE update for java-11-openjdk
- SUSE update for java-25-openjdk
- Anolis OS update for java-1.8.0-openjdk
- Multiple vulnerabilities in IBM WebSphere Service Registry and Repository
- Ubuntu update for openjdk-21-crac
- Ubuntu update for openjdk-21
- Ubuntu update for openjdk-lts
- Ubuntu update for openjdk-8
- Ubuntu update for openjdk-17
- Ubuntu update for openjdk-17-crac
- Ubuntu update for openjdk-25-crac
- Ubuntu update for openjdk-25
- SUSE update for java-17-openjdk
- SUSE update for java-21-openjdk
- SUSE update for java-1_8_0-ibm
- Multiple vulnerabilities in IBM DevOps Code ClearCase
- SUSE update for java-1_8_0-openj9
- SUSE update for java-1_8_0-ibm
- Debian update for openjdk-25
- Anolis OS update for java-21-openjdk
- Anolis OS update for java-17-openjdk
- Multiple vulnerabilities in Red Hat build of Keycloak 26.2
- SUSE update for java-11-openjdk
- SUSE update for java-17-openjdk
- SUSE update for java-1_8_0-openjdk
- SUSE update for java-1_8_0-openjdk
- Multiple vulnerabilities in IBM Sterling Transformation Extender
- Multiple vulnerabilities in IBM OpenPages
- Multiple vulnerabilities in IBM Integration Designer
- Multiple vulnerabilities in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines
- Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM TXSeries for Multiplatforms
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM Tivoli Composite Application Manager for Applications WebSphere MQ Monitoring Agent
- Multiple vulnerabilities in IBM Tivoli Monitoring for Virtual Environments Base
- Multiple vulnerabilities in IBM Cognos Command Center
- Multiple vulnerabilities in IBM Tivoli Netcool/OMNIbus_GUI
- RSA Governance and Lifecycle update for Oracle Databse
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Sterling Connect:Direct for Microsoft Windows
- Multiple vulnerabilities in IBM Sterling Connect:Direct File Agent
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in IBM CICS Transaction Gateway for Multiplatforms and CICS Transaction Gateway Desktop Edition
- Red Hat Enterprise Linux 8 update for java-1.8.0-ibm
- Multiple vulnerabilities in IBM Knowledge Catalog and IBM Master Data Management On Cloud Pak for Data
- Multiple vulnerabilities in IBM Informix Dynamic Server
- Multiple vulnerabilities in IBM Control Center
- Multiple vulnerabilities in IBM Transformation Extender Advanced
- Anolis OS update for java-1.8.0-openjdk
- Multiple vulnerabilities in IBM Communications Server (CS) for Data Center Deployment, CS for Linux, and CS for Linux on System z
- Multiple vulnerabilities in IBM Sterling Connect:Direct for UNIX
- Multiple vulnerabilities in IBM Sterling Connect:Direct FTP+
- Multiple vulnerabilities in IBM SPSS Modeler
- Multiple vulnerabilities in IBM Tivoli System Automation for Multiplatforms
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in IBM Storage Protect Operations Center
- Multiple vulnerabilities in IBM WebSphere Extreme Scale
- Multiple vulnerabilities in IBM Storage Protect Backup-Archive Client, IBM Storage Protect for Virtual Environments and IBM Storage Protect for Space Management
- Anolis OS update for java-17-openjdk
- Multiple vulnerabilities in IBM Power Hardware Management Console (HMC)
- Multiple vulnerabilities in IBM Db2
- Multiple vulnerabilities in IBM Copy Services Manager
- Multiple vulnerabilities in IBM Tivoli Netcool Impact
- Multiple vulnerabilities in IBM DataPower Gateway
- Multiple vulnerabilities in IBM Planning Analytics Local
- Multiple vulnerabilities in IBM i
- Multiple vulnerabilities in IBM Storage Defender - Resiliency Service
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Certificate Management
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Console
- Multiple vulnerabilities in IBM Application Performance Management
- Multiple vulnerabilities in IBM Enterprise Content Management System Monitor
- Multiple vulnerabilities in IBM Guardium Data Protection
- Multiple vulnerabilities in IBM Tivoli Application Dependency Discovery Manager
- Multiple vulnerabilities in IBM Content Collector for SAP Applications
- Multiple vulnerabilities in IBM Tivoli System Automation Application Manager
- Multiple vulnerabilities in IBM PowerVM Novalink
- Multiple vulnerabilities in IBM SPSS Statistics Client and Server
- Multiple vulnerabilities in IBM Rational Business Developer
- IBM MQ Appliance update for Java SE
- Multiple vulnerabilities in IBM Watson Discovery Cartridge
- Multiple vulnerabilities in IBM MQ
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM Security Verify Directory
- Multiple vulnerabilities in IBM Engineering Systems Design Rhapsody
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Common Licensing
- Multiple vulnerabilities in IBM B2B Advanced Communications