Bug 2338992 (CVE-2025-21502) - CVE-2025-21502 openjdk: Enhance array handling (Oracle CPU 2025-01)
Summary: CVE-2025-21502 openjdk: Enhance array handling (Oracle CPU 2025-01)
Keywords:
Status: NEW
Alias: CVE-2025-21502
Deadline: 2025-01-21
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-01-20 11:33 UTC by OSIDB Bzimport
Modified: 2025-04-15 16:01 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2025:1154 0 None None None 2025-02-06 16:43:00 UTC

Description OSIDB Bzimport 2025-01-20 11:33:22 UTC
Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data.

Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security.

Oracle Critical Patch Update Advisory - January 2025:
https://www.oracle.com/security-alerts/cpujan2025.html#AppendixJAVA

Comment 3 errata-xmlrpc 2025-02-06 16:42:56 UTC
This issue has been addressed in the following products:

  RHINT Camel-K 1.10.9

Via RHSA-2025:1154 https://access.redhat.com/errata/RHSA-2025:1154


Note You need to log in before you can comment on or make changes to this bug.