Improper input validation in Oracle Java SE - CVE-2023-22067

 

Improper input validation in Oracle Java SE - CVE-2023-22067

Published: October 17, 2023


Vulnerability identifier: #VU82140
CSH Severity: Medium
CVSS v4 BT: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-22067
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The vulnerability exists due to improper input validation within the CORBA component in Oracle Java SE. A remote non-authenticated attacker can exploit this vulnerability to manipulate data.


Affected software

Oracle Java SE
Rational Business Developer (RBD)
OpenJDK Java (for Middleware)
IBM Java SDK
IBM CICS TX Advanced
IBM App Connect Enterprise
IBM CICS TX Standard
Oracle Linux
IBM AIX
Amazon Linux AMI
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
Red Hat Enterprise Linux Server
Anolis OS
CentOS
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
SUSE Enterprise Storage
IBM i
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Legacy Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
IBM Business Automation Workflow
IBM SPSS Collaboration and Deployment Services
IBM Tivoli Monitoring
IBM Security Access Manager for Enterprise Single-Sign On
IBM Intelligent Operations Center
Red Hat Migration Toolkit for Applications
IBM Tivoli Business Service Manager
IBM Maximo Asset Management
IBM Rational Build Forge
CICS Transaction Gateway
Rational Application Developer
IBM Security Verify Governance
IBM Sterling Transformation Extender
IBM SPSS Modeler
IBM Cloud Application Business Insights
IBM Sterling Connect:Direct FTP+
IBM Cloud Transformation Advisor
Content Collector for Microsoft SharePoint
Content Collector for Email
Content Collector for File Systems
IBM Tivoli System Automation Application Manager
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Spectrum Control
IBM Sterling Secure Proxy
IBM Sterling Connect:Direct Web Services
IBM Sterling Control Center
IBM Tivoli Netcool Impact
Netcool/OMNIbus
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
WebSphere Service Registry and Repository
WebSphere eXtreme Scale
IBM Workload Scheduler
IBM Integration Bus
IBM Power Hardware Management Console (HMC)
Rational Functional Tester (RFT)
Dell EMC OpenManage Server Administrator
EMC Data Protection Advisor
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
IBM VIOS
IBM WebSphere Application Server
Rational Software Architect Designer (RSAD)
IBM Cloud Pak for Watson AIOps
Informix JDBC Driver
Rational Synergy
Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines
Tivoli Monitoring for Virtual Environments Base
Dell EMC NetWorker Runtime Environment (NRE)
IBM OpenPages with Watson
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
IBM InfoSphere Identity Insight
DB2 Query Management Facility
Storage Defender – Data Protect
IBM Planning Analytics Workspace
Tivoli System Automation for Multiplatforms
IBM Secure External Authentication Server
Db2 Big SQL
IBM Semeru Runtimes
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Space Management
Storage Protect Server
Storage Virtualize
WebSphere Service Registry and Repository Studio
Cognos Transformer
CloudBoost Virtual Appliance
Robotic Process Automation for Cloud Pak
IBM Cloud Pak for Multicloud Management
IBM Copy Services Manager
IBM App Connect Professional
IBM Tivoli Application Dependency Discovery Manager
Sterling Connect:Direct Browser User Interface
IBM Data Risk Manager
Juniper Secure Analytics (JSA)
IBM Security SOAR
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
openjdk-8-jdk-headless (Ubuntu package)
openjdk-8-jdk (Ubuntu package)
openjdk-8-jre-headless (Ubuntu package)
openjdk-8-jre (Ubuntu package)
openjdk-8-jre-zero (Ubuntu package)
openjdk-8-jre-jamvm (Ubuntu package)
java
java-1_8_0-ibm-devel
java-1_8_0-ibm
java-1_8_0-ibm-plugin
java-1_8_0-ibm-alsa
java-1_8_0-ibm-src
java-1_8_0-ibm-demo
java-1_8_0-ibm-devel-32bit
java-1_8_0-ibm-32bit
java-1.8.0-ibm (Red Hat package)
java-1.8.0-openjdk-accessibility
java-1.8.0-openjdk-accessibility-debug
java-1.8.0-openjdk-debug
java-1.8.0-openjdk-demo
java-1.8.0-openjdk
java-1.8.0-openjdk-headless-debug
java-1.8.0-openjdk-demo-debug
java-1.8.0-openjdk-devel
java-1.8.0-openjdk-headless
java-1.8.0-openjdk-devel-debug
java-1.8.0-openjdk-src
java-1.8.0-openjdk-src-debug
java-1.8.0-openjdk-javadoc
java-1.8.0-openjdk-javadoc-debug
java-1.8.0-openjdk-javadoc-zip
java-1.8.0-openjdk-javadoc-zip-debug
java-1.8.0-openjdk (Red Hat package)
java-1_8_0-openjdk-devel
java-1_8_0-openjdk
java-1_8_0-openjdk-demo-debuginfo
java-1_8_0-openjdk-headless
java-1_8_0-openjdk-headless-debuginfo
java-1_8_0-openjdk-debugsource
java-1_8_0-openjdk-demo
java-1_8_0-openjdk-debuginfo
java-1_8_0-openjdk-devel-debuginfo
java-1_8_0-openjdk-src
java-1_8_0-openjdk-accessibility
java-1_8_0-openjdk-javadoc
java-1_8_0-openj9-demo
java-1_8_0-openj9-javadoc
java-1_8_0-openj9-accessibility
java-1_8_0-openj9-debugsource
java-1_8_0-openj9-src
java-1_8_0-openj9-demo-debuginfo
java-1_8_0-openj9-debuginfo
java-1_8_0-openj9-headless
java-1_8_0-openj9
java-1_8_0-openj9-devel
java-1_8_0-openj9-devel-debuginfo
java-1_8_0-openj9-headless-debuginfo
openjdk-11 (Debian package)
IBM Security Guardium
IBM Cognos Controller
IBM Qradar SIEM
IBM License Metric Tool
IBM InfoSphere Information Server
Planning Analytics Local
IBM Cloud Pak System
IBM Storage Scale System
RSA Authentication Manager
Informix Dynamic Server

How to mitigate CVE-2023-22067

Install updates from vendor's website.

IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Intelligent Operations Center - update to 5.2.5
Red Hat Migration Toolkit for Applications - update to 6.1.4
Rational Synergy - update to 7.2.2.7
Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines - update to 7.2.10
Tivoli Monitoring for Virtual Environments Base - update to 7.3.7
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Dell EMC NetWorker Runtime Environment (NRE) - update to 8.0.19
IBM Rational Build Forge - update to 8.0.0.26
OpenJDK Java (for Middleware) - update to 8.0.392
IBM Cognos Controller - update to 11.0.1.0.3
openjdk-8-jdk-headless (Ubuntu package) - addressed in versions Ubuntu Pro, 8u392-ga-1~20.04, 8u392-ga-1~22.04, 8u392-ga-1~23.04, 8u392-ga-1~23.10
openjdk-8-jdk (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 8u392-ga-1~20.04, 8u392-ga-1~22.04, 8u392-ga-1~23.04, 8u392-ga-1~23.10
openjdk-8-jre-headless (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 8u392-ga-1~20.04, 8u392-ga-1~22.04, 8u392-ga-1~23.04, 8u392-ga-1~23.10
openjdk-8-jre (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 8u392-ga-1~20.04, 8u392-ga-1~22.04, 8u392-ga-1~23.04, 8u392-ga-1~23.10
openjdk-8-jre-zero (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 8u392-ga-1~20.04, 8u392-ga-1~22.04, 8u392-ga-1~23.04, 8u392-ga-1~23.10
openjdk-8-jre-jamvm (Ubuntu package) - update to Ubuntu Pro
IBM Cloud Application Business Insights - addressed in versions 1.1.7.9, 1.1.8.4
IBM Sterling Connect:Direct FTP+ - update to 1.3.0.0.25
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-40
java - addressed in versions 1.8.0-openjdk-devel-1.8.0.392.b08-2, 1.8.0-openjdk-devel-slowdebug-1.8.0.392.b08-2, 1.8.0-openjdk-openjfx-devel-1.8.0.392.b08-2, 1.8.0-openjdk-openjfx-devel-slowdebug-1.8.0.392.b08-2, 1.8.0-openjdk-accessibility-1.8.0.392.b08-2, 1.8.0-openjdk-accessibility-slowdebug-1.8.0.392.b08-2, 1.8.0-openjdk-1.8.0.392.b08-2, 1.8.0-openjdk-src-1.8.0.392.b08-2, 1.8.0-openjdk-src-slowdebug-1.8.0.392.b08-2, 1.8.0-openjdk-debugsource-1.8.0.392.b08-2, 1.8.0-openjdk-debuginfo-1.8.0.392.b08-2, 1.8.0-openjdk-demo-1.8.0.392.b08-2, 1.8.0-openjdk-demo-slowdebug-1.8.0.392.b08-2, 1.8.0-openjdk-headless-1.8.0.392.b08-2, 1.8.0-openjdk-headless-slowdebug-1.8.0.392.b08-2, 1.8.0-openjdk-javadoc-1.8.0.392.b08-2, 1.8.0-openjdk-javadoc-zip-1.8.0.392.b08-2, 1.8.0-openjdk-openjfx-1.8.0.392.b08-2, 1.8.0-openjdk-openjfx-slowdebug-1.8.0.392.b08-2, 1.8.0-openjdk-slowdebug-1.8.0.392.b08-2
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr8.15-30.117.1, 1.8.0_sr8.15-150000.3.83.1
java-1_8_0-ibm - addressed in versions 1.8.0_sr8.15-30.117.1, 1.8.0_sr8.15-150000.3.83.1
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr8.15-30.117.1, 1.8.0_sr8.15-150000.3.83.1
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr8.15-30.117.1, 1.8.0_sr8.15-150000.3.83.1
java-1_8_0-ibm-src - update to 1.8.0_sr8.15-150000.3.83.1
java-1_8_0-ibm-demo - update to 1.8.0_sr8.15-150000.3.83.1
java-1_8_0-ibm-devel-32bit - update to 1.8.0_sr8.15-150000.3.83.1
java-1_8_0-ibm-32bit - update to 1.8.0_sr8.15-150000.3.83.1
java-1.8.0-ibm (Red Hat package) - addressed in versions 1.8.0.8.15-1.el8_9, 1.8.0.8.15-1jpp.1.el7
java-1.8.0-openjdk-accessibility - addressed in versions 1.8.0.392.b08-2, 1.8.0.392.b08-4.0.2
java-1.8.0-openjdk-accessibility-debug - update to 1.8.0.392.b08-2
java-1.8.0-openjdk-debug - update to 1.8.0.392.b08-2
java-1.8.0-openjdk-demo - addressed in versions 1.8.0.392.b08-2, 1.8.0.392.b08-4.0.2
java-1.8.0-openjdk - addressed in versions 1.8.0.392.b08-2, 1.8.0.392.b08-4.0.2
java-1.8.0-openjdk-headless-debug - update to 1.8.0.392.b08-2
java-1.8.0-openjdk-demo-debug - update to 1.8.0.392.b08-2
java-1.8.0-openjdk-devel - addressed in versions 1.8.0.392.b08-2, 1.8.0.392.b08-4.0.2
java-1.8.0-openjdk-headless - addressed in versions 1.8.0.392.b08-2, 1.8.0.392.b08-4.0.2
java-1.8.0-openjdk-devel-debug - update to 1.8.0.392.b08-2
java-1.8.0-openjdk-src - addressed in versions 1.8.0.392.b08-2, 1.8.0.392.b08-4.0.2
java-1.8.0-openjdk-src-debug - update to 1.8.0.392.b08-2
java-1.8.0-openjdk-javadoc - addressed in versions 1.8.0.392.b08-2, 1.8.0.392.b08-4.0.2
java-1.8.0-openjdk-javadoc-debug - update to 1.8.0.392.b08-2
java-1.8.0-openjdk-javadoc-zip - addressed in versions 1.8.0.392.b08-2, 1.8.0.392.b08-4.0.2
java-1.8.0-openjdk-javadoc-zip-debug - update to 1.8.0.392.b08-2
java-1.8.0-openjdk (Red Hat package) - addressed in versions 1.8.0.392.b08-2.el7_9, 1.8.0.392.b08-2.el8_1, 1.8.0.392.b08-2.el8_2, 1.8.0.392.b08-2.el8_4, 1.8.0.392.b08-2.el8_6, 1.8.0.392.b08-2.el9_0, 1.8.0.392.b08-3.el9, 1.8.0.392.b08-4.el8
java-1_8_0-openjdk-devel - addressed in versions 1.8.0.392-27.93.1, 1.8.0.392-150000.3.85.1
java-1_8_0-openjdk - addressed in versions 1.8.0.392-27.93.1, 1.8.0.392-150000.3.85.1
java-1_8_0-openjdk-demo-debuginfo - addressed in versions 1.8.0.392-27.93.1, 1.8.0.392-150000.3.85.1
java-1_8_0-openjdk-headless - addressed in versions 1.8.0.392-27.93.1, 1.8.0.392-150000.3.85.1
java-1_8_0-openjdk-headless-debuginfo - addressed in versions 1.8.0.392-27.93.1, 1.8.0.392-150000.3.85.1
java-1_8_0-openjdk-debugsource - addressed in versions 1.8.0.392-27.93.1, 1.8.0.392-150000.3.85.1
java-1_8_0-openjdk-demo - addressed in versions 1.8.0.392-27.93.1, 1.8.0.392-150000.3.85.1
java-1_8_0-openjdk-debuginfo - addressed in versions 1.8.0.392-27.93.1, 1.8.0.392-150000.3.85.1
java-1_8_0-openjdk-devel-debuginfo - addressed in versions 1.8.0.392-27.93.1, 1.8.0.392-150000.3.85.1
java-1_8_0-openjdk-src - update to 1.8.0.392-150000.3.85.1
java-1_8_0-openjdk-accessibility - update to 1.8.0.392-150000.3.85.1
java-1_8_0-openjdk-javadoc - update to 1.8.0.392-150000.3.85.1
java-1_8_0-openj9-demo - update to 1.8.0.392-150200.3.39.1
java-1_8_0-openj9-javadoc - update to 1.8.0.392-150200.3.39.1
java-1_8_0-openj9-accessibility - update to 1.8.0.392-150200.3.39.1
java-1_8_0-openj9-debugsource - update to 1.8.0.392-150200.3.39.1
java-1_8_0-openj9-src - update to 1.8.0.392-150200.3.39.1
java-1_8_0-openj9-demo-debuginfo - update to 1.8.0.392-150200.3.39.1
java-1_8_0-openj9-debuginfo - update to 1.8.0.392-150200.3.39.1
java-1_8_0-openj9-headless - update to 1.8.0.392-150200.3.39.1
java-1_8_0-openj9 - update to 1.8.0.392-150200.3.39.1
java-1_8_0-openj9-devel - update to 1.8.0.392-150200.3.39.1
java-1_8_0-openj9-devel-debuginfo - update to 1.8.0.392-150200.3.39.1
java-1_8_0-openj9-headless-debuginfo - update to 1.8.0.392-150200.3.39.1
Storage Defender – Data Protect - update to 2.0.1
IBM Data Risk Manager - update to 2.0.6.20
Planning Analytics Local - update to 2.0.9.20
IBM Planning Analytics Workspace - update to 2.1.4
IBM Cloud Pak System - update to 2.3.4.0
IBM Cloud Transformation Advisor - update to 3.8.1
Content Collector for Microsoft SharePoint - update to 4.0.1.15 IF009
Content Collector for Email - update to 4.0.1.15 IF009
Content Collector for File Systems - update to 4.0.1.15 IF009
IBM Tivoli System Automation Application Manager - addressed in versions 4.1.0.3.0.12, 4.1.0.4.0.9, 4.1.0.5.0.7, 4.1.0.6.0.1
Tivoli System Automation for Multiplatforms - addressed in versions 4.1.0.4.0.20, 4.1.0.5.0.14, 4.1.0.7.0.7, 4.1.1.0.0.3, 4.1.1.1.0.1
IBM Decision Optimization for Cloud Pak for Data - update to 4.8
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM Storage Scale System - addressed in versions 5.1.2.15, 5.1.9.2
IBM Spectrum Control - update to 5.4.12
IBM Secure External Authentication Server - addressed in versions 6.0.3.0 iFix 10, 6.1.0.0 iFix 06
IBM Sterling Secure Proxy - addressed in versions 6.0.3 iFix 11, 6.1.0 iFix 03
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.23, 6.2.0.22, 6.3.0.6
IBM Sterling Control Center - addressed in versions 6.2.1.0.13, 6.3.1.0.2
IBM Tivoli Netcool Impact - update to 7.1.0.33
IBM Java SDK - addressed in versions 7.1.5.20, 8.0-8.15
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
Db2 Big SQL - update to 7.7
IBM Semeru Runtimes - addressed in versions 8.0.392.0, 11.0.21.0, 17.0.9.0
Netcool/OMNIbus - update to 8.1.0.32
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Storage Protect Client - update to 8.1.22.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.22.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.22.0
Storage Protect for Space Management - update to 8.1.22.0
Storage Protect Server - update to 8.1.23
IBM TXSeries for Multiplatforms - addressed in versions 8.2.0.3, 9.1.0.3
Storage Virtualize - addressed in versions 8.4.0.13, 8.5.0.11, 8.6.0.3, 8.6.2.0
IBM WebSphere Application Server - update to 8.5.5.25
WebSphere Service Registry and Repository - update to 8.5.6.3 IJ49208
WebSphere Service Registry and Repository Studio - update to 8.5.6.3 IJ49208
WebSphere eXtreme Scale - update to 8.6.1.6 PH59543
RSA Authentication Manager - addressed in versions 8.7 SP1 Patch 3, 8.7 SP2 Patch 1
IBM License Metric Tool - update to 9.2.34
IBM Workload Scheduler - addressed in versions 9.5.0.7, 10.1.0.5, 10.2.2
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix24, 11.1.0.0 ifix17
IBM Integration Bus - update to 10.1.0.2
IBM Power Hardware Management Console (HMC) - addressed in versions 10.1.1020.0 SP3, 10.2.1040.0 SP2, 10.3.1050.0 SP1
Rational Functional Tester (RFT) - update to 11.0.0
IBM App Connect Enterprise - addressed in versions 11.0.0.24, 12.0.11.0
Dell EMC OpenManage Server Administrator - update to 11.0.21
openjdk-11 (Debian package) - update to 11.0.21+9-1~deb11u1
IBM CICS TX Standard - update to 11.1.0.0 ifix17
Cognos Transformer - addressed in versions 11.2.4 FP4, 12.0.3
Informix Dynamic Server - addressed in versions 12.10.xC16W2, 14.10.xC11
EMC Data Protection Advisor - update to 19.9.93
CloudBoost Virtual Appliance - update to 19.12.0.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.30, 23.0.2.2
IBM Robotic Process Automation - addressed in versions 21.0.7.13, 23.0.13
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.13, 23.0.13
IBM Security SOAR - update to 51.0.0.2

External References

Related Security Bulletins