OpenJDK: Incorrect exception processing during deserialization in BeanContextSupport (Serialization, 8224909)
Published Jan 15, 2020
3.7
LOWCVSS 3.1
EPSS 4.02%
Description
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
Affected products
-
- Version Java SE Embedded: 8u231StatusaffectedConstraints-
- Version Java SE: 7u241, 8u231, 11.0.5, 13.0.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Oracle Corporation | Java | n/a |
|
Configuration 1
Configuration 2
- 8.0
- 6.0
- 7.0
- 7.7
- 8.1
- 6.0
- 7.0
- 7.7
- 7.7
- 6.0
- 7.0
Configuration 3
- 7
- 7
- 7
- 7
- 8
- 8
- 8
- 8
- 8
- 8
- 8
- 8
- 8
- 8
- 8
- 8
- 8
- 8
- 8
- 8
- 8
- 11
- 11.0.1
- 11.0.2
- 11.0.3
- 11.0.4
- 11.0.5
- 13
- 13.0.1
Configuration 4
- 8.0
- 9.0
- 10.0
Configuration 5
- 16.04
- 18.04
- 19.10
Configuration 7
- 5.9.0
- 5.9.1
- 5.10.0
- 5.10.0
- 5.10.0
- 5.10.0
- 5.10.0
- 5.10.0
- 5.10.0
- ≥ 7.3
- ≥ 9.5
- n/a
- n/a
- ≥ 11.0.0 · ≤ 11.60.3
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
Red Hat Enterprise Linux 6
java-1.7.0-openjdk-1:1.7.0.251-2.6.21.0.el6_10
Fixed · RHSA-2020:0632
Red Hat Enterprise Linux 6
java-1.8.0-openjdk-1:1.8.0.242.b07-1.el6_10
Fixed · RHSA-2020:0157
Red Hat Enterprise Linux 6 Supplementary
java-1.7.1-ibm-1:1.7.1.4.60-1jpp.1.el6_10
Fixed · RHSA-2020:0467
Red Hat Enterprise Linux 6 Supplementary
java-1.8.0-ibm-1:1.8.0.6.5-1jpp.1.el6_10
Fixed · RHSA-2020:0469
Red Hat Enterprise Linux 7
java-1.7.0-openjdk-1:1.7.0.251-2.6.21.0.el7_7
Fixed · RHSA-2020:0541
Red Hat Enterprise Linux 7
java-1.8.0-openjdk-1:1.8.0.242.b08-0.el7_7
Fixed · RHSA-2020:0196
Red Hat Enterprise Linux 7
java-11-openjdk-1:11.0.6.10-1.el7_7
Fixed · RHSA-2020:0122
Red Hat Enterprise Linux 7 Supplementary
java-1.7.1-ibm-1:1.7.1.4.60-1jpp.1.el7
Fixed · RHSA-2020:0468
Red Hat Enterprise Linux 7 Supplementary
java-1.8.0-ibm-1:1.8.0.6.5-1jpp.1.el7
Fixed · RHSA-2020:0470
Red Hat Enterprise Linux 8
java-1.8.0-ibm-1:1.8.0.6.5-1.el8_1
Fixed · RHSA-2020:0465
Red Hat Enterprise Linux 8
java-1.8.0-openjdk-1:1.8.0.242.b08-0.el8_1
Fixed · RHSA-2020:0202
Red Hat Enterprise Linux 8
java-11-openjdk-1:11.0.6.10-0.el8_1
Fixed · RHSA-2020:0128
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
java-1.8.0-openjdk-1:1.8.0.242.b08-0.el8_0
Fixed · RHSA-2020:0231
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
java-11-openjdk-1:11.0.6.10-0.el8_0
Fixed · RHSA-2020:0232
Red Hat Satellite 5.8
java-1.8.0-ibm-1:1.8.0.6.5-1jpp.1.el6_10
Fixed · RHSA-2020:0856
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | java-1.7.0-openjdk-1:1.7.0.251-2.6.21.0.el6_10 | Fixed | RHSA-2020:0632 |
| Red Hat Enterprise Linux 6 | java-1.8.0-openjdk-1:1.8.0.242.b07-1.el6_10 | Fixed | RHSA-2020:0157 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.7.1-ibm-1:1.7.1.4.60-1jpp.1.el6_10 | Fixed | RHSA-2020:0467 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.8.0-ibm-1:1.8.0.6.5-1jpp.1.el6_10 | Fixed | RHSA-2020:0469 |
| Red Hat Enterprise Linux 7 | java-1.7.0-openjdk-1:1.7.0.251-2.6.21.0.el7_7 | Fixed | RHSA-2020:0541 |
| Red Hat Enterprise Linux 7 | java-1.8.0-openjdk-1:1.8.0.242.b08-0.el7_7 | Fixed | RHSA-2020:0196 |
| Red Hat Enterprise Linux 7 | java-11-openjdk-1:11.0.6.10-1.el7_7 | Fixed | RHSA-2020:0122 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.7.1-ibm-1:1.7.1.4.60-1jpp.1.el7 | Fixed | RHSA-2020:0468 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.8.0-ibm-1:1.8.0.6.5-1jpp.1.el7 | Fixed | RHSA-2020:0470 |
| Red Hat Enterprise Linux 8 | java-1.8.0-ibm-1:1.8.0.6.5-1.el8_1 | Fixed | RHSA-2020:0465 |
| Red Hat Enterprise Linux 8 | java-1.8.0-openjdk-1:1.8.0.242.b08-0.el8_1 | Fixed | RHSA-2020:0202 |
| Red Hat Enterprise Linux 8 | java-11-openjdk-1:11.0.6.10-0.el8_1 | Fixed | RHSA-2020:0128 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | java-1.8.0-openjdk-1:1.8.0.242.b08-0.el8_0 | Fixed | RHSA-2020:0231 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | java-11-openjdk-1:11.0.6.10-0.el8_0 | Fixed | RHSA-2020:0232 |
| Red Hat Satellite 5.8 | java-1.8.0-ibm-1:1.8.0.6.5-1jpp.1.el6_10 | Fixed | RHSA-2020:0856 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (30)
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00050.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00060.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0122 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0128 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0157 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0196 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0202 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0231 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0232 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0465 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0467 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0468 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0469 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0470 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0541 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0632 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-2583 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1790444 Issue Tracking
- https://kc.mcafee.com/corporate/index?page=content&id=SB10315 x_refsource_CONFIRMThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/02/msg00034.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-2583
- https://seclists.org/bugtraq/2020/Feb/22 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2020/Jan/24 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202101-19 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200122-0003/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4257-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-2583
- https://www.debian.org/security/2020/dsa-4605 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2020/dsa-4621 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2020.html x_refsource_MISCPatchVendor Advisory
Change history (0)
No recorded changes yet.