High Threat Security Alert (A22-04-20): Multiple Vulnerabilities in Oracle Java and Oracle Products (April 2022)

High Threat Security Alert (A22-04-20): Multiple Vulnerabilities in Oracle Java and Oracle Products (April 2022)

Description:


Oracle has released the Critical Patch Update (CPU) Advisory with collections of patches for multiple security vulnerabilities found in Java SE and various Oracle products. The list of security updates can be found at:


https://www.oracle.com/security-alerts/cpuapr2022.html


Reports indicate that the remote code execution vulnerabilities (CVE-2022-22963 and CVE-2022-22965) are at high risk of exploitation. System administrators are advised to take immediate actions to patch your affected systems to mitigate the elevated risk of cyber attacks.


 


Affected Systems:


  • Oracle Java SE

  • Database

  • Oracle Linux and Virtualization

  • Oracle MySQL Product Suite

  • Oracle and Sun Systems Products Suite

  • Fusion Applications and Middleware

  • NoSQL Database

  • A complete list of the affected products can be found at:


    https://www.oracle.com/security-alerts/cpuapr2022.html


     


    Impact:


    Depending on the vulnerability exploited, a successful attack could lead to remote code execution, data tampering, denial of service, information disclosure or security restriction bypass on an affected system.


     


    Recommendation:


    Patches for affected systems are available. Users of the affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.


    For Oracle Java SE products, please refer to the following link:


  • Java Platform SE 8u331 (JDK and JRE)

  • Java Platform SE 11.0.15 (JDK and JRE)

  • Java Platform SE 17.0.3 (JDK and JRE)

  • Java Platform SE 18.0.1 (JDK and JRE)

  • htt ..

    Support the originator by clicking the read the rest link below.