Bug 2228078 (CVE-2022-40609) - CVE-2022-40609 IBM JDK: unsafe deserialization flaw in the Object Request Broker (ORB)
Summary: CVE-2022-40609 IBM JDK: unsafe deserialization flaw in the Object Request Bro...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2022-40609
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2215911 2215912 2215913
Blocks: 2228082
TreeView+ depends on / blocked
 
Reported: 2023-08-01 10:35 UTC by Mauro Matteo Cascella
Modified: 2023-08-08 15:55 UTC (History)
1 user (show)

Fixed In Version: java-1.8.0-ibm 8.0.8.5
Clone Of:
Environment:
Last Closed: 2023-08-01 17:37:49 UTC
Embargoed:


Attachments (Terms of Use)

Description Mauro Matteo Cascella 2023-08-01 10:35:11 UTC
IBM SDK, Java Technology Edition could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the system.

Reference:
https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities#IBM_Security_Update_August_2023
https://www.ibm.com/support/pages/node/7017032

Comment 1 Mauro Matteo Cascella 2023-08-01 10:53:14 UTC
This issue was fixed in IBM JDK 8 SR8 FP5 (8.0.8.5). The java-1.8.0-ibm packages as shipped in Red Hat Enterprise Linux 7 and 8 were previously updated to a version that contains the fix via the following errata:

java-1.8.0-ibm in Red Hat Enterprise Linux 7 Supplementary
https://access.redhat.com/errata/RHSA-2023:4160

java-1.8.0-ibm in Red Hat Enterprise Linux 8
https://access.redhat.com/errata/RHSA-2023:4103

Comment 2 Product Security DevOps Team 2023-08-01 17:37:48 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-40609


Note You need to log in before you can comment on or make changes to this bug.