Man-in-the-Middle (MitM) attack in Oracle GraalVM Enterprise Edition - CVE-2021-35550
Published: October 19, 2021 / Updated: January 3, 2023
Oracle GraalVM Enterprise Edition
IBM Spectrum Virtualize
Solutions Enabler Virtual Appliance
IBM Watson Explorer Deep Analytics Edition Foundational Components
IBM Rational Directory Administrator (RDA)
IBM Connect Direct for Microsoft Windows
IBM Spectrum Protect Backup-Archive Client
IBM Watson Explorer Foundational Components
IBM Watson Explorer Content Analytics Studio
IBM Watson Explorer Foundational Components Annotation Administration Console
IBM Watson Explorer Analytical Components
IBM Watson Explorer Deep Analytics Edition oneWEX
IBM Watson Explorer Deep Analytics Edition Analytical Components
IBM Sterling Connect:Direct File Agent
IBM Enterprise Content Management System Monitor
SecurID Governance and Lifecycle
IBM Business Process Manager
IBM Business Automation Workflow
z/Transaction Processing Facility ( z/TPF)
IBM Cloud Application Business Insights
Netcool Operations Insight
IBM Cloud Pak for Multicloud Management Monitoring
IBM Cloud Transformation Advisor
IBM Decision Optimization Center (DOC)
IBM Intelligent Operations Center
IBM Sterling Control Center
IBM MQ
CICS Transaction Gateway
WebSphere Service Registry and Repository
IBM Rational Build Forge
IBM TXSeries for Multiplatforms
WebSphere eXtreme Scale
IBM Rational ClearQuest
Rational Application Developer
IBM InfoSphere Information Server for Cloud
Dell EMC Data Protection Search
SPSS Statistics
IBM Operations Analytics Predictive Insights
IBM Watson Knowledge Catalog in Cloud Pak for Data
Session Smart Router
IBM Tivoli Monitoring
IBM Security Verify Governance
EMC Data Protection Advisor
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
CentOS
IBM Security Identity Manager Virtual Appliance
IBM AIX
IBM i
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Anolis OS
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Legacy Software
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
RSA Identity Governance and Lifecycle
IBM Rational Directory Server (RDS)
IBM Security Identity Governance and Intelligence (IGI)
SecurID Authentication Manager
EMC Integrated Data Protection Appliance
WebSphere Internet Pass-Thru
IBM Tivoli Application Dependency Discovery Manager
IBM Cloud Pak System
IBM VIOS
Oracle Java SE
Rational Business Developer (RBD)
IBM CICS TX Advanced
IBM CICS TX Standard
IBM Spectrum Protect for Space Management
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
openjdk-11 (Debian package)
java-11-openjdk (Red Hat package)
SUSE Linux Enterprise Module for Packagehub Subpackages
java-1_7_0-openjdk-headless-debuginfo
java-1_7_0-openjdk-headless
java-1_7_0-openjdk-devel-debuginfo
java-1_7_0-openjdk-devel
java-1_7_0-openjdk-demo-debuginfo
java-1_7_0-openjdk-demo
java-1_7_0-openjdk-debugsource
java-1_7_0-openjdk-debuginfo
java-1_7_0-openjdk
java-1.7.1-ibm (Red Hat package)
java
java-1.8.0-ibm (Red Hat package)
java-1.8.0-openjdk-headless
java-1.8.0-openjdk
java-1.8.0-openjdk-accessibility
java-1.8.0-openjdk-javadoc-zip
java-1.8.0-openjdk-javadoc
java-1.8.0-openjdk-src
java-1.8.0-openjdk-demo
java-1.8.0-openjdk (Red Hat package)
java-1_8_0-openjdk-devel-debuginfo
java-1_8_0-openjdk-headless
java-1_8_0-openjdk-devel
java-1_8_0-openjdk-demo-debuginfo
java-1_8_0-openjdk-demo
java-1_8_0-openjdk-debugsource
java-1_8_0-openjdk
java-1_8_0-openjdk-headless-debuginfo
java-1_8_0-openjdk-debuginfo
openjdk-8-jre (Ubuntu package)
openjdk-8-jre-zero (Ubuntu package)
openjdk-8-jre-headless (Ubuntu package)
java-11-openjdk-headless
java-11-openjdk-devel
java-11-openjdk-demo
java-11-openjdk-debugsource
java-11-openjdk
java-11-openjdk-javadoc
java-11-openjdk-jmods
java-11-openjdk-static-libs
java-11-openjdk-src
java-11-openjdk-javadoc-zip
openjdk-11-jre (Ubuntu package)
openjdk-11-jre-headless (Ubuntu package)
openjdk-11-jre-zero (Ubuntu package)
java-11-openjdk-demo-slowdebug
java-11-openjdk-devel-slowdebug
java-11-openjdk-jmods-slowdebug
java-11-openjdk-src-slowdebug
java-11-openjdk-slowdebug
java-11-openjdk-debuginfo
java-11-openjdk-headless-slowdebug
java-latest-openjdk-debugsource
java-latest-openjdk
java-latest-openjdk-javadoc-zip
java-latest-openjdk-devel
java-latest-openjdk-headless
java-latest-openjdk-javadoc
java-latest-openjdk-debuginfo
java-latest-openjdk-src
java-latest-openjdk-jmods
java-latest-openjdk-demo
IBM Spectrum Protect for Virtual Environments: Data Protection for VMware
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V
Event Streams
IBM Cognos Command Center
EMC ESRS Policy Manager
IBM InfoSphere Information Server
IBM DB2
FlashSystem 900 9840-AE1 and 9843-AE1
FlashSystem 900 9840-AE2 and 9843-AE2
FlashSystem 900 9840-AE3 and 9843-AE3
IBM Secure External Authentication Server
PowerStore T
IBM Security Directory Server
IBM Security Directory Suite
Solutions Enabler
Unisphere 360
Unisphere for PowerMax
Unisphere for PowerMax Virtual Appliance
VASA Provider Standalone
CloudBoost Virtual Appliance
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
IBM Cognos Analytics
Juniper Junos Space
Contrail Networking
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The vulnerability exists due to the JSSE component in Oracle GraalVM Enterprise Edition offers cipher suites in the wrong way, which causes weaker cipher suites to be offered ahead of the strong ones. A remote non-authenticated attacker can exploit this vulnerability to gain access to sensitive information.