CVE-2022-21476
CVE-2022-21476 is a high-severity vulnerability in Oracle Graalvm with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-284.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v2: 5.0
- EPSS exploit prediction: 4% (90th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-284
- Affected product: Oracle Graalvm
- Published:
- Last modified:
Description
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Frequently asked questions
- What is CVE-2022-21476?
- Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- How severe is CVE-2022-21476?
- CVE-2022-21476 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2022-21476 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 4% (90th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2022-21476?
- CVE-2022-21476 primarily affects Oracle Graalvm. In total, 151 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2022-21476?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2022-21476 published?
- CVE-2022-21476 was published on 2022-04-19 and last updated on 2026-06-17.
References
- https://lists.debian.org/debian-lts-announce/2022/05/msg00017.html
- https://security.netapp.com/advisory/ntap-20220429-0006/
- https://www.debian.org/security/2022/dsa-5128
- https://www.debian.org/security/2022/dsa-5131
- https://www.oracle.com/security-alerts/cpuapr2022.html
Affected products (151)
- cpe:2.3:a:oracle:graalvm:20.3.5:*:*:*:enterprise:*:*:*
- cpe:2.3:a:oracle:graalvm:21.3.1:*:*:*:enterprise:*:*:*
- cpe:2.3:a:oracle:graalvm:22.0.0.2:*:*:*:enterprise:*:*:*
- cpe:2.3:a:oracle:jdk:7.0:update_331:*:*:*:*:*:*
- cpe:2.3:a:oracle:jdk:8.0:update_321:*:*:*:*:*:*
- cpe:2.3:a:oracle:jdk:11.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jdk:17.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jdk:18:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
- cpe:2.3:a:netapp:cloud_insights_acquisition_unit:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:cloud_secure_agent:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:e-series_santricity_storage_manager:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:e-series_santricity_web_services:-:*:*:*:*:web_services_proxy:*:*
- cpe:2.3:a:netapp:element_software:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:santricity_unified_manager:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
- cpe:2.3:a:azul:zulu:7.52:*:*:*:*:*:*:*
- cpe:2.3:a:azul:zulu:8.60:*:*:*:*:*:*:*
- cpe:2.3:a:azul:zulu:11.54:*:*:*:*:*:*:*
- cpe:2.3:a:azul:zulu:13.46:*:*:*:*:*:*:*
- cpe:2.3:a:azul:zulu:15.38:*:*:*:*:*:*:*
- cpe:2.3:a:azul:zulu:17.32:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:*:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:7:-:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:7:update1:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:7:update10:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:7:update101:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:7:update11:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:7:update111:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:7:update121:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:7:update13:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:7:update131:*:*:*:*:*:*
More vulnerabilities in Oracle Graalvm
- CVE-2021-22931 — Critical (CVSS 9.8): Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to…
- CVE-2021-29921 — Critical (CVSS 9.8): In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string.…
- CVE-2019-15606 — Critical (CVSS 9.8): Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on…
- CVE-2019-15605 — Critical (CVSS 9.8): HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
- CVE-2019-17560 — Critical (CVSS 9.1): The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads.…
- CVE-2023-41993 — High (CVSS 8.8): The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead…
All CVEs affecting Oracle Graalvm →
Other CWE-284 (Improper Access Control) vulnerabilities
- CVE-2026-76607 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.3 - ???.
- CVE-2026-20315 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering…
- CVE-2026-70921 — Critical (CVSS 10.0): Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The…
- CVE-2026-66803 — Critical (CVSS 10.0): Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
- CVE-2026-58630 — Critical (CVSS 10.0): Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-60358 — Critical (CVSS 10.0): Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).…
Browse all CWE-284 (Improper Access Control) vulnerabilities →