Improper input validation in Oracle GraalVM Enterprise Edition - CVE-2026-21932
Published: January 20, 2026
Vulnerability identifier: #VU121728
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-21932
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
The vulnerability exists due to improper input validation within the AWT, JavaFX component in Oracle GraalVM Enterprise Edition. A remote non-authenticated attacker can exploit this vulnerability to manipulate data.
Affected software
Oracle GraalVM Enterprise Edition
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
Debian Linux
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
IBM i
SUSE Package Hub 15
Legacy Module
Basesystem Module
openSUSE Leap
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
Ubuntu
WebSphere Service Registry and Repository
SecurID Governance and Lifecycle
IBM Sterling Connect:Direct FTP+
IBM Content Collector for SAP Applications
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Control Center
Communications Server for Linux on System z
Communications Server for Data Center Deployment
IBM Tivoli Netcool Impact
IBM Tivoli Netcool/OMNIbus WebGUI
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM SPSS Collaboration and Deployment Services
WebSphere eXtreme Scale
IBM Common Licensing
IBM Transformation Extender Advanced
IBM Sterling Transformation Extender
IBM SPSS Modeler
IBM Tivoli System Automation Application Manager
IBM Sterling Connect:Direct for UNIX
IBM MQ
SPSS Statistics
RSA Identity Governance and Lifecycle
B2B Advanced Communications
Storage Defender - Resiliency Service
DataStage on Cloud Pak for Data
Communications Server for Linux
Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines
Tivoli Monitoring for Virtual Environments Base
Storage Protect Operations Center
Storage Protect Server
IBM OpenPages with Watson
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
IBM Security Verify Directory
IBM Engineering Systems Design Rhapsody
Integration Designer
PowerVM NovaLink
Tivoli System Automation for Multiplatforms
IBM Sterling Connect:Direct for Microsoft Windows
Tivoli Composite Application Manager for Applications WebSphere MQ Monitoring Agent
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect Client
Guardium Data Protection
Robotic Process Automation for Cloud Pak
Voice Gateway
IBM Sterling Connect:Direct File Agent
IBM Enterprise Content Management System Monitor
IBM Copy Services Manager
Planning Analytics Local
IBM Tivoli Application Dependency Discovery Manager
Oracle Java SE
Rational Business Developer (RBD)
IBM CICS TX Standard
IBM App Connect Enterprise
Oracle GraalVM for JDK
IBM Java SDK
IBM CICS TX Advanced
IBM Cognos Command Center
IBM DB2
java-1_8_0-ibm-plugin
java-1_8_0-ibm-alsa
java-1_8_0-ibm-devel
java-1_8_0-ibm
java-1_8_0-ibm-32bit
java-1_8_0-ibm-src
java-1_8_0-ibm-demo
java-1_8_0-ibm-devel-32bit
java-1_8_0-openjdk-headless-debuginfo
java-1_8_0-openjdk-debugsource
java-1_8_0-openjdk-headless
java-1_8_0-openjdk-demo
java-1_8_0-openjdk-debuginfo
java-1_8_0-openjdk-devel
java-1_8_0-openjdk
java-1_8_0-openjdk-demo-debuginfo
java-1_8_0-openjdk-devel-debuginfo
java-1_8_0-openjdk-accessibility
java-1_8_0-openjdk-javadoc
java-1_8_0-openjdk-src
java-1_8_0-openj9-debuginfo
java-1_8_0-openj9-devel
java-1_8_0-openj9-demo
java-1_8_0-openj9-headless-debuginfo
java-1_8_0-openj9-headless
java-1_8_0-openj9-debugsource
java-1_8_0-openj9-devel-debuginfo
java-1_8_0-openj9-accessibility
java-1_8_0-openj9-demo-debuginfo
java-1_8_0-openj9
java-1_8_0-openj9-src
java-1_8_0-openj9-javadoc
openjdk-8 (Ubuntu package)
java-11-openjdk-demo
java-11-openjdk-devel
java-11-openjdk
java-11-openjdk-debugsource
java-11-openjdk-debuginfo
java-11-openjdk-headless
java-11-openjdk-src
java-11-openjdk-devel-debuginfo
java-11-openjdk-jmods
java-11-openjdk-headless-debuginfo
java-11-openjdk-javadoc
openjdk-lts (Ubuntu package)
java-17-openjdk
java-17-openjdk-jmods
java-17-openjdk-devel
java-17-openjdk-devel-debuginfo
java-17-openjdk-debuginfo
java-17-openjdk-debugsource
java-17-openjdk-demo
java-17-openjdk-headless
java-17-openjdk-headless-debuginfo
java-17-openjdk-src
java-17-openjdk-javadoc
openjdk-17-crac (Ubuntu package)
openjdk-17 (debian package)
openjdk-17 (Ubuntu package)
java-21-openjdk-devel-debuginfo
java-21-openjdk-demo
java-21-openjdk-src
java-21-openjdk
java-21-openjdk-headless-debuginfo
java-21-openjdk-devel
java-21-openjdk-headless
java-21-openjdk-jmods
java-21-openjdk-debugsource
java-21-openjdk-debuginfo
java-21-openjdk-javadoc
openjdk-21-crac (Ubuntu package)
openjdk-21 (Debian package)
openjdk-21 (Ubuntu package)
java-25-openjdk-devel
java-25-openjdk
java-25-openjdk-demo
java-25-openjdk-debuginfo
java-25-openjdk-headless-debuginfo
java-25-openjdk-headless
java-25-openjdk-devel-debuginfo
openjdk-25-crac (Ubuntu package)
openjdk-25 (Debian package)
openjdk-25 (Ubuntu package)
Informix Dynamic Server
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
Debian Linux
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
IBM i
SUSE Package Hub 15
Legacy Module
Basesystem Module
openSUSE Leap
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
Ubuntu
WebSphere Service Registry and Repository
SecurID Governance and Lifecycle
IBM Sterling Connect:Direct FTP+
IBM Content Collector for SAP Applications
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Control Center
Communications Server for Linux on System z
Communications Server for Data Center Deployment
IBM Tivoli Netcool Impact
IBM Tivoli Netcool/OMNIbus WebGUI
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM SPSS Collaboration and Deployment Services
WebSphere eXtreme Scale
IBM Common Licensing
IBM Transformation Extender Advanced
IBM Sterling Transformation Extender
IBM SPSS Modeler
IBM Tivoli System Automation Application Manager
IBM Sterling Connect:Direct for UNIX
IBM MQ
SPSS Statistics
RSA Identity Governance and Lifecycle
B2B Advanced Communications
Storage Defender - Resiliency Service
DataStage on Cloud Pak for Data
Communications Server for Linux
Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines
Tivoli Monitoring for Virtual Environments Base
Storage Protect Operations Center
Storage Protect Server
IBM OpenPages with Watson
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
IBM Security Verify Directory
IBM Engineering Systems Design Rhapsody
Integration Designer
PowerVM NovaLink
Tivoli System Automation for Multiplatforms
IBM Sterling Connect:Direct for Microsoft Windows
Tivoli Composite Application Manager for Applications WebSphere MQ Monitoring Agent
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect Client
Guardium Data Protection
Robotic Process Automation for Cloud Pak
Voice Gateway
IBM Sterling Connect:Direct File Agent
IBM Enterprise Content Management System Monitor
IBM Copy Services Manager
Planning Analytics Local
IBM Tivoli Application Dependency Discovery Manager
Oracle Java SE
Rational Business Developer (RBD)
IBM CICS TX Standard
IBM App Connect Enterprise
Oracle GraalVM for JDK
IBM Java SDK
IBM CICS TX Advanced
IBM Cognos Command Center
IBM DB2
java-1_8_0-ibm-plugin
java-1_8_0-ibm-alsa
java-1_8_0-ibm-devel
java-1_8_0-ibm
java-1_8_0-ibm-32bit
java-1_8_0-ibm-src
java-1_8_0-ibm-demo
java-1_8_0-ibm-devel-32bit
java-1_8_0-openjdk-headless-debuginfo
java-1_8_0-openjdk-debugsource
java-1_8_0-openjdk-headless
java-1_8_0-openjdk-demo
java-1_8_0-openjdk-debuginfo
java-1_8_0-openjdk-devel
java-1_8_0-openjdk
java-1_8_0-openjdk-demo-debuginfo
java-1_8_0-openjdk-devel-debuginfo
java-1_8_0-openjdk-accessibility
java-1_8_0-openjdk-javadoc
java-1_8_0-openjdk-src
java-1_8_0-openj9-debuginfo
java-1_8_0-openj9-devel
java-1_8_0-openj9-demo
java-1_8_0-openj9-headless-debuginfo
java-1_8_0-openj9-headless
java-1_8_0-openj9-debugsource
java-1_8_0-openj9-devel-debuginfo
java-1_8_0-openj9-accessibility
java-1_8_0-openj9-demo-debuginfo
java-1_8_0-openj9
java-1_8_0-openj9-src
java-1_8_0-openj9-javadoc
openjdk-8 (Ubuntu package)
java-11-openjdk-demo
java-11-openjdk-devel
java-11-openjdk
java-11-openjdk-debugsource
java-11-openjdk-debuginfo
java-11-openjdk-headless
java-11-openjdk-src
java-11-openjdk-devel-debuginfo
java-11-openjdk-jmods
java-11-openjdk-headless-debuginfo
java-11-openjdk-javadoc
openjdk-lts (Ubuntu package)
java-17-openjdk
java-17-openjdk-jmods
java-17-openjdk-devel
java-17-openjdk-devel-debuginfo
java-17-openjdk-debuginfo
java-17-openjdk-debugsource
java-17-openjdk-demo
java-17-openjdk-headless
java-17-openjdk-headless-debuginfo
java-17-openjdk-src
java-17-openjdk-javadoc
openjdk-17-crac (Ubuntu package)
openjdk-17 (debian package)
openjdk-17 (Ubuntu package)
java-21-openjdk-devel-debuginfo
java-21-openjdk-demo
java-21-openjdk-src
java-21-openjdk
java-21-openjdk-headless-debuginfo
java-21-openjdk-devel
java-21-openjdk-headless
java-21-openjdk-jmods
java-21-openjdk-debugsource
java-21-openjdk-debuginfo
java-21-openjdk-javadoc
openjdk-21-crac (Ubuntu package)
openjdk-21 (Debian package)
openjdk-21 (Ubuntu package)
java-25-openjdk-devel
java-25-openjdk
java-25-openjdk-demo
java-25-openjdk-debuginfo
java-25-openjdk-headless-debuginfo
java-25-openjdk-headless
java-25-openjdk-devel-debuginfo
openjdk-25-crac (Ubuntu package)
openjdk-25 (Debian package)
openjdk-25 (Ubuntu package)
Informix Dynamic Server
How to mitigate CVE-2026-21932
Install updates from vendor's website.
B2B Advanced Communications - update to 1.0.0.13
Voice Gateway - addressed in versions 1.0.8.19, 1.0.8.25
IBM Sterling Connect:Direct FTP+ - update to 1.3.0.4
IBM Sterling Connect:Direct File Agent - update to 1.4.0.5 iFix006
Storage Defender - Resiliency Service - update to 2.1.3
Planning Analytics Local - update to 2.1.19
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
DataStage on Cloud Pak for Data - update to 5.3.1 patch 3
IBM Sterling Control Center - addressed in versions 6.3.1.0.7, 6.4.1.0.1, 6.4.2.0.1
IBM Tivoli Netcool Impact - update to 7.1.0.38
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix16
Storage Protect Operations Center - update to 8.2.1
Storage Protect Server - update to 8.2.1
WebSphere eXtreme Scale - update to 8.6.1.6 PH70422
Rational Business Developer (RBD) - addressed in versions 9.6.1.1, 9.7.1
IBM Security Verify Directory - update to 11.0.0.1
IBM Engineering Systems Design Rhapsody - addressed in versions 10.0.0.5, 10.0.1.0.5, 10.0.2.0.4
IBM Transformation Extender Advanced - addressed in versions 10.0.1.11 1iFix, 10.0.2.1 1iFix
IBM Cognos Command Center - update to 10.2.5 FP1 IF3
IBM CICS TX Standard - update to 11.1.0.0 ifix39
IBM App Connect Enterprise - addressed in versions 12.0.12.23, 13.0.6.2
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr8.60-30.146.1, 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr8.60-30.146.1, 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr8.60-30.146.1, 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm - addressed in versions 1.8.0_sr8.60-30.146.1, 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-32bit - update to 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-src - update to 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-demo - update to 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-devel-32bit - update to 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-openjdk-headless-debuginfo - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-debugsource - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-headless - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-demo - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-debuginfo - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-devel - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-demo-debuginfo - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-devel-debuginfo - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-accessibility - update to 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-javadoc - update to 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-src - update to 1.8.0.482-150000.3.117.1
java-1_8_0-openj9-debuginfo - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-devel - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-demo - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-headless-debuginfo - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-headless - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-debugsource - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-devel-debuginfo - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-accessibility - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-demo-debuginfo - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9 - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-src - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-javadoc - update to 1.8.0.482-150200.3.63.1
PowerVM NovaLink - addressed in versions 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422
IBM Tivoli System Automation Application Manager - addressed in versions 4.1.0.3.0.18, 4.1.0.4.0.15, 4.1.0.5.0.13, 4.1.0.6.0.7, 4.1.0.7.0.2
Tivoli System Automation for Multiplatforms - addressed in versions 4.1.0.4.0.26, 4.1.0.5.0.20, 4.1.0.6.0.15, 4.1.0.7.0.15, 4.1.1.0.0.9, 4.1.1.1.0.10
IBM Enterprise Content Management System Monitor - update to 5.7.000 FP2
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.3.0.6.iFix033, 6.4.0.4.iFix017
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.3.0.6.39, 6.4.0.4.10
IBM Copy Services Manager - update to 6.3.17
IBM Java SDK - addressed in versions 7.1.5.29, 8.0.8.60
Tivoli Composite Application Manager for Applications WebSphere MQ Monitoring Agent - update to 7.3.0 Fix Pack 4
openjdk-8 (Ubuntu package) - addressed in versions 8u482-ga~us1-0ubuntu1~16.04, 8u482-ga~us1-0ubuntu1~18.04, 8u482-ga~us1-0ubuntu1~20.04, 8u482-ga~us1-0ubuntu1~22.04, 8u482-ga~us1-0ubuntu1~24.04, 8u482-ga~us1-0ubuntu1~25.10
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect Client - update to 8.2.1
IBM MQ - addressed in versions 9.1.0.36, 9.2.0.42, 9.3.0.40, 9.4.5.1
IBM CICS TX Advanced - update to 10.1.0.0 ifix46
java-11-openjdk-demo - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk-devel - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk-debugsource - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk-debuginfo - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk-headless - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk-src - update to 11.0.30.0-150000.3.135.1
java-11-openjdk-devel-debuginfo - update to 11.0.30.0-150000.3.135.1
java-11-openjdk-jmods - update to 11.0.30.0-150000.3.135.1
java-11-openjdk-headless-debuginfo - update to 11.0.30.0-150000.3.135.1
java-11-openjdk-javadoc - update to 11.0.30.0-150000.3.135.1
openjdk-lts (Ubuntu package) - addressed in versions 11.0.30+7-1ubuntu1~18.04, 11.0.30+7-1ubuntu1~20.04, 11.0.30+7-1ubuntu1~22.04, 11.0.30+7-1ubuntu1~24.04, 11.0.30+7-1ubuntu1~25.10
Guardium Data Protection - addressed in versions 12.0p140, 12.2.1
Informix Dynamic Server - update to 12.10.xC16W6
java-17-openjdk - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-jmods - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-devel - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-devel-debuginfo - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-debuginfo - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-debugsource - update to 17.0.18.0-150400.3.63.1
java-17-openjdk-demo - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-headless - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-headless-debuginfo - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-src - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-javadoc - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
openjdk-17-crac (Ubuntu package) - update to 17.0.18+8-0ubuntu1~25.10
openjdk-17 (debian package) - update to 17.0.18+8-1~deb12u1
openjdk-17 (Ubuntu package) - addressed in versions 17.0.18+8-1~18.04, 17.0.18+8-1~20.04, 17.0.18+8-1~22.04.1, 17.0.18+8-1~24.04.1, 17.0.18+8-1~25.10.1
java-21-openjdk-devel-debuginfo - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-demo - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-src - update to 21.0.10.0-150600.3.23.1
java-21-openjdk - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-headless-debuginfo - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-devel - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-headless - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-jmods - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-debugsource - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-debuginfo - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-javadoc - update to 21.0.10.0-150600.3.23.1
openjdk-21-crac (Ubuntu package) - update to 21.0.10+7-0ubuntu1~25.10
openjdk-21 (Debian package) - update to 21.0.10+7-1~deb13u1
openjdk-21 (Ubuntu package) - addressed in versions 21.0.10+7-1~20.04, 21.0.10+7-1~22.04, 21.0.10+7-1~24.04, 21.0.10+7-1~25.10
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.6, 30.0.2
java-25-openjdk-devel - update to 25.0.2.0-150700.15.7.1
java-25-openjdk - update to 25.0.2.0-150700.15.7.1
java-25-openjdk-demo - update to 25.0.2.0-150700.15.7.1
java-25-openjdk-debuginfo - update to 25.0.2.0-150700.15.7.1
java-25-openjdk-headless-debuginfo - update to 25.0.2.0-150700.15.7.1
java-25-openjdk-headless - update to 25.0.2.0-150700.15.7.1
java-25-openjdk-devel-debuginfo - update to 25.0.2.0-150700.15.7.1
openjdk-25-crac (Ubuntu package) - update to 25.0.2+10-0ubuntu1~25.10
openjdk-25 (Debian package) - update to 25.0.2+10-1~deb13u2
openjdk-25 (Ubuntu package) - addressed in versions 25.0.2+10-1~22.04, 25.0.2+10-1~24.04, 25.0.2+10-1~25.10
SPSS Statistics - addressed in versions 28.0.1.1 IF017, 29.0.2.0 IF018, 30.0.0.0 IF014, 31.0.2.0 IF06
Voice Gateway - addressed in versions 1.0.8.19, 1.0.8.25
IBM Sterling Connect:Direct FTP+ - update to 1.3.0.4
IBM Sterling Connect:Direct File Agent - update to 1.4.0.5 iFix006
Storage Defender - Resiliency Service - update to 2.1.3
Planning Analytics Local - update to 2.1.19
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
DataStage on Cloud Pak for Data - update to 5.3.1 patch 3
IBM Sterling Control Center - addressed in versions 6.3.1.0.7, 6.4.1.0.1, 6.4.2.0.1
IBM Tivoli Netcool Impact - update to 7.1.0.38
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix16
Storage Protect Operations Center - update to 8.2.1
Storage Protect Server - update to 8.2.1
WebSphere eXtreme Scale - update to 8.6.1.6 PH70422
Rational Business Developer (RBD) - addressed in versions 9.6.1.1, 9.7.1
IBM Security Verify Directory - update to 11.0.0.1
IBM Engineering Systems Design Rhapsody - addressed in versions 10.0.0.5, 10.0.1.0.5, 10.0.2.0.4
IBM Transformation Extender Advanced - addressed in versions 10.0.1.11 1iFix, 10.0.2.1 1iFix
IBM Cognos Command Center - update to 10.2.5 FP1 IF3
IBM CICS TX Standard - update to 11.1.0.0 ifix39
IBM App Connect Enterprise - addressed in versions 12.0.12.23, 13.0.6.2
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr8.60-30.146.1, 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr8.60-30.146.1, 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr8.60-30.146.1, 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm - addressed in versions 1.8.0_sr8.60-30.146.1, 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-32bit - update to 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-src - update to 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-demo - update to 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-ibm-devel-32bit - update to 1.8.0_sr8.60-150000.3.112.1
java-1_8_0-openjdk-headless-debuginfo - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-debugsource - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-headless - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-demo - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-debuginfo - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-devel - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-demo-debuginfo - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-devel-debuginfo - addressed in versions 1.8.0.482-27.125.1, 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-accessibility - update to 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-javadoc - update to 1.8.0.482-150000.3.117.1
java-1_8_0-openjdk-src - update to 1.8.0.482-150000.3.117.1
java-1_8_0-openj9-debuginfo - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-devel - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-demo - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-headless-debuginfo - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-headless - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-debugsource - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-devel-debuginfo - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-accessibility - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-demo-debuginfo - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9 - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-src - update to 1.8.0.482-150200.3.63.1
java-1_8_0-openj9-javadoc - update to 1.8.0.482-150200.3.63.1
PowerVM NovaLink - addressed in versions 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422
IBM Tivoli System Automation Application Manager - addressed in versions 4.1.0.3.0.18, 4.1.0.4.0.15, 4.1.0.5.0.13, 4.1.0.6.0.7, 4.1.0.7.0.2
Tivoli System Automation for Multiplatforms - addressed in versions 4.1.0.4.0.26, 4.1.0.5.0.20, 4.1.0.6.0.15, 4.1.0.7.0.15, 4.1.1.0.0.9, 4.1.1.1.0.10
IBM Enterprise Content Management System Monitor - update to 5.7.000 FP2
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.3.0.6.iFix033, 6.4.0.4.iFix017
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.3.0.6.39, 6.4.0.4.10
IBM Copy Services Manager - update to 6.3.17
IBM Java SDK - addressed in versions 7.1.5.29, 8.0.8.60
Tivoli Composite Application Manager for Applications WebSphere MQ Monitoring Agent - update to 7.3.0 Fix Pack 4
openjdk-8 (Ubuntu package) - addressed in versions 8u482-ga~us1-0ubuntu1~16.04, 8u482-ga~us1-0ubuntu1~18.04, 8u482-ga~us1-0ubuntu1~20.04, 8u482-ga~us1-0ubuntu1~22.04, 8u482-ga~us1-0ubuntu1~24.04, 8u482-ga~us1-0ubuntu1~25.10
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect Client - update to 8.2.1
IBM MQ - addressed in versions 9.1.0.36, 9.2.0.42, 9.3.0.40, 9.4.5.1
IBM CICS TX Advanced - update to 10.1.0.0 ifix46
java-11-openjdk-demo - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk-devel - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk-debugsource - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk-debuginfo - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk-headless - addressed in versions 11.0.30.0-3.96.1, 11.0.30.0-150000.3.135.1
java-11-openjdk-src - update to 11.0.30.0-150000.3.135.1
java-11-openjdk-devel-debuginfo - update to 11.0.30.0-150000.3.135.1
java-11-openjdk-jmods - update to 11.0.30.0-150000.3.135.1
java-11-openjdk-headless-debuginfo - update to 11.0.30.0-150000.3.135.1
java-11-openjdk-javadoc - update to 11.0.30.0-150000.3.135.1
openjdk-lts (Ubuntu package) - addressed in versions 11.0.30+7-1ubuntu1~18.04, 11.0.30+7-1ubuntu1~20.04, 11.0.30+7-1ubuntu1~22.04, 11.0.30+7-1ubuntu1~24.04, 11.0.30+7-1ubuntu1~25.10
Guardium Data Protection - addressed in versions 12.0p140, 12.2.1
Informix Dynamic Server - update to 12.10.xC16W6
java-17-openjdk - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-jmods - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-devel - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-devel-debuginfo - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-debuginfo - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-debugsource - update to 17.0.18.0-150400.3.63.1
java-17-openjdk-demo - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-headless - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-headless-debuginfo - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-src - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
java-17-openjdk-javadoc - addressed in versions 17.0.18.0-150400.3.63.1, 17.0.18.0-160000.1.1
openjdk-17-crac (Ubuntu package) - update to 17.0.18+8-0ubuntu1~25.10
openjdk-17 (debian package) - update to 17.0.18+8-1~deb12u1
openjdk-17 (Ubuntu package) - addressed in versions 17.0.18+8-1~18.04, 17.0.18+8-1~20.04, 17.0.18+8-1~22.04.1, 17.0.18+8-1~24.04.1, 17.0.18+8-1~25.10.1
java-21-openjdk-devel-debuginfo - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-demo - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-src - update to 21.0.10.0-150600.3.23.1
java-21-openjdk - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-headless-debuginfo - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-devel - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-headless - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-jmods - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-debugsource - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-debuginfo - update to 21.0.10.0-150600.3.23.1
java-21-openjdk-javadoc - update to 21.0.10.0-150600.3.23.1
openjdk-21-crac (Ubuntu package) - update to 21.0.10+7-0ubuntu1~25.10
openjdk-21 (Debian package) - update to 21.0.10+7-1~deb13u1
openjdk-21 (Ubuntu package) - addressed in versions 21.0.10+7-1~20.04, 21.0.10+7-1~22.04, 21.0.10+7-1~24.04, 21.0.10+7-1~25.10
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.6, 30.0.2
java-25-openjdk-devel - update to 25.0.2.0-150700.15.7.1
java-25-openjdk - update to 25.0.2.0-150700.15.7.1
java-25-openjdk-demo - update to 25.0.2.0-150700.15.7.1
java-25-openjdk-debuginfo - update to 25.0.2.0-150700.15.7.1
java-25-openjdk-headless-debuginfo - update to 25.0.2.0-150700.15.7.1
java-25-openjdk-headless - update to 25.0.2.0-150700.15.7.1
java-25-openjdk-devel-debuginfo - update to 25.0.2.0-150700.15.7.1
openjdk-25-crac (Ubuntu package) - update to 25.0.2+10-0ubuntu1~25.10
openjdk-25 (Debian package) - update to 25.0.2+10-1~deb13u2
openjdk-25 (Ubuntu package) - addressed in versions 25.0.2+10-1~22.04, 25.0.2+10-1~24.04, 25.0.2+10-1~25.10
SPSS Statistics - addressed in versions 28.0.1.1 IF017, 29.0.2.0 IF018, 30.0.0.0 IF014, 31.0.2.0 IF06
External References
Related Security Bulletins
- Multiple vulnerabilities in Oracle GraalVM Enterprise Edition
- Multiple vulnerabilities in Oracle Java SE
- Multiple vulnerabilities in Oracle GraalVM for JDK
- Debian update for openjdk-17
- Multiple vulnerabilities in IBM SDK, Java Technology Edition
- Debian update for openjdk-21
- SUSE update for java-11-openjdk
- SUSE update for java-25-openjdk
- Multiple vulnerabilities in IBM WebSphere Service Registry and Repository
- Ubuntu update for openjdk-21-crac
- Ubuntu update for openjdk-21
- Ubuntu update for openjdk-lts
- Ubuntu update for openjdk-8
- Ubuntu update for openjdk-17
- Ubuntu update for openjdk-17-crac
- Ubuntu update for openjdk-25-crac
- Ubuntu update for openjdk-25
- SUSE update for java-17-openjdk
- SUSE update for java-21-openjdk
- SUSE update for java-1_8_0-ibm
- SUSE update for java-1_8_0-openj9
- SUSE update for java-1_8_0-ibm
- Debian update for openjdk-25
- SUSE update for java-11-openjdk
- SUSE update for java-17-openjdk
- SUSE update for java-1_8_0-openjdk
- SUSE update for java-1_8_0-openjdk
- Multiple vulnerabilities in IBM Sterling Transformation Extender
- Multiple vulnerabilities in IBM OpenPages
- Multiple vulnerabilities in IBM Integration Designer
- Multiple vulnerabilities in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines
- Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM TXSeries for Multiplatforms
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM Tivoli Composite Application Manager for Applications WebSphere MQ Monitoring Agent
- Multiple vulnerabilities in IBM Tivoli Monitoring for Virtual Environments Base
- Multiple vulnerabilities in IBM Cognos Command Center
- Multiple vulnerabilities in IBM Tivoli Netcool/OMNIbus_GUI
- RSA Governance and Lifecycle update for Oracle Databse
- Multiple vulnerabilities in IBM Sterling Connect:Direct for Microsoft Windows
- Multiple vulnerabilities in IBM Sterling Connect:Direct File Agent
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in IBM CICS Transaction Gateway for Multiplatforms and CICS Transaction Gateway Desktop Edition
- Multiple vulnerabilities in IBM Informix Dynamic Server
- Multiple vulnerabilities in IBM Control Center
- Multiple vulnerabilities in IBM Transformation Extender Advanced
- Multiple vulnerabilities in IBM Communications Server (CS) for Data Center Deployment, CS for Linux, and CS for Linux on System z
- Multiple vulnerabilities in IBM Sterling Connect:Direct for UNIX
- Multiple vulnerabilities in IBM Sterling Connect:Direct FTP+
- Multiple vulnerabilities in IBM SPSS Modeler
- Multiple vulnerabilities in IBM Tivoli System Automation for Multiplatforms
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in IBM Storage Protect Operations Center
- Multiple vulnerabilities in IBM WebSphere Extreme Scale
- Multiple vulnerabilities in IBM Storage Protect Backup-Archive Client, IBM Storage Protect for Virtual Environments and IBM Storage Protect for Space Management
- Multiple vulnerabilities in IBM Db2
- Multiple vulnerabilities in IBM Copy Services Manager
- Multiple vulnerabilities in IBM Tivoli Netcool Impact
- Multiple vulnerabilities in IBM Planning Analytics Local
- Multiple vulnerabilities in IBM i
- Multiple vulnerabilities in IBM Storage Defender - Resiliency Service
- Multiple vulnerabilities in IBM Application Performance Management
- Multiple vulnerabilities in IBM Enterprise Content Management System Monitor
- Multiple vulnerabilities in IBM Guardium Data Protection
- Multiple vulnerabilities in IBM Tivoli Application Dependency Discovery Manager
- Multiple vulnerabilities in IBM Content Collector for SAP Applications
- Multiple vulnerabilities in IBM Tivoli System Automation Application Manager
- Multiple vulnerabilities in IBM PowerVM Novalink
- Multiple vulnerabilities in IBM SPSS Statistics Client and Server
- Multiple vulnerabilities in IBM Rational Business Developer
- Multiple vulnerabilities in IBM Watson Discovery Cartridge
- Multiple vulnerabilities in IBM MQ
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM Security Verify Directory
- Multiple vulnerabilities in IBM Engineering Systems Design Rhapsody
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Multiple vulnerabilities in IBM Common Licensing
- Multiple vulnerabilities in IBM B2B Advanced Communications