Intelligence View
⚡ tsecurity.de Intelligence
CVE-2022-21282 | Oracle Java SE 7u321/8u311/11.0.13/17.01 JAXP information disclosure (Nessus ID 208596)
A vulnerability, which was classified as critical, has been found in Oracle Java SE 7u321/8u311/11.0.13/17.01. Affected by this issue is some unknown…
A vulnerability, which was classified as critical, has been found in Oracle Java SE 7u321/8u311/11.0.13/17.01. Affected by this issue is some unknown functionality of the component JAXP. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2022-21282. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
This vulnerability is handled as CVE-2022-21282. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
CVSS 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Impact: 1.41 | Exploitability: 3.89
AVN
Netzwerk (Remote)
Aus der Ferne über das Internet ohne Vorbedingungen exploitbar.
ACL
Niedrig (Low)
Wiederholbar und deterministisch ohne spezielle Race Conditions ausnutzbar.
PRN
Keine (Unauthenticated)
Vollständig unauthentifiziert ohne Benutzerkonto exploitbar.
UIN
Keine (Zero-Click)
Autonom ohne menschliches Zutun ausführbar (Zero-Click Exploitation).
SU
Unverändert (Scope Unchanged)
Auswirkungen verbleiben isoliert in der angreifbaren Anwendungskomponente.
CL
Gering (Teilabfluss)
Teilweiser oder kein Datenabfluss.
IN
Keine
Teilweise oder keine Manipulation.
AN
Keine
Teilweise oder keine Beeinträchtigung.
BSI-Warnung (Deutschland)CVE-2022-21282
Xerox FreeFlow Print Server: Mehrere Schwachstellen21.06.2022Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit Administratorrechten14.06.2022Xerox FreeFlow Print Server: Mehrere Schwachstellen11.05.2022CISA-SSVC-Triage (vulnrichment)CVE-2022-21282
Exploitation: none (Keine bekannte Ausnutzung)Automatable: yes (Automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2025-05-20T16:54:44.345635Z · CISA Coordinator
Advisory Radar
Offizielles Hersteller-Update verfügbar
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller hat ein verifiziertes Patch-Release herausgegeben. Sofortiges Rollout auf Test- und Produktivsystemen empfohlen.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Oracle Critical Patch Update (CPU) Verifiziertoracle.com
-
Web Referencesecurity.netapp.com
-
Debian Security Tracker Verifiziertdebian.org
-
Debian Security Tracker Verifiziertdebian.org
-
Debian Security Tracker Verifiziertdebian.org