{"schema_version":"1.7.3","id":"SUSE-SU-2022:3092-1","published":"2022-09-06T05:51:30Z","modified":"2026-02-04T02:27:45.495733Z","related":["CVE-2021-41041","CVE-2022-21426","CVE-2022-21434","CVE-2022-21443","CVE-2022-21476","CVE-2022-21496","CVE-2022-21540","CVE-2022-21541","CVE-2022-34169"],"upstream":["CVE-2021-41041","CVE-2022-21426","CVE-2022-21434","CVE-2022-21443","CVE-2022-21476","CVE-2022-21496","CVE-2022-21540","CVE-2022-21541","CVE-2022-34169"],"summary":"Security update for java-1_8_0-openj9","details":"This update for java-1_8_0-openj9 fixes the following issues:\n\n- Updated to OpenJDK 8u345 build 01 with OpenJ9 0.33.0 virtual machine:\n  - CVE-2022-34169: Fixed an integer truncation issue in the Xalan\n    Java XSLT library that occurred when processing malicious\n    stylesheets (bsc#1201684).\n  - CVE-2022-21541: Fixed a potential bypass of sandbox restrictions\n    in the Hotspot component (bsc#1201692).\n  - CVE-2022-21540: Fixed a potential bypass of sandbox restrictions\n    in the Hotspot component (bsc#1201694).\n\n- Updated to OpenJDK 8u332 build 09 with OpenJ9 0.32.0 virtual machine:\n  - CVE-2021-41041: Failed an issue that could allow unverified methods\n    to be invoked using MethodHandles (bsc#1198935).\n  - CVE-2022-21426: Fixed a remote partial denial of service issue\n    (component: JAXP) (bsc#1198672).\n  - CVE-2022-21434: Fixed an issue that could allow a remote attacker\n    to update, insert or delete data (component: Libraries) (bsc#1198674).\n  - CVE-2022-21443: Fixed a remote partial denial of service issue\n    (component: Libraries) (bsc#1198675).\n  - CVE-2022-21476: Fixed an issue that could allow unauthorized\n    access to confidential data (component: Libraries) (bsc#1198671).\n  - CVE-2022-21496: Fixed an issue that could allow a remote attacker\n    to update, insert or delete data (component: JNDI) (bsc#1198673).\n","affected":[{"package":{"name":"java-1_8_0-openj9","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/java-1_8_0-openj9&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0.345-150200.3.24.1"}]}],"ecosystem_specific":{"binaries":[{"java-1_8_0-openj9":"1.8.0.345-150200.3.24.1","java-1_8_0-openj9-accessibility":"1.8.0.345-150200.3.24.1","java-1_8_0-openj9-demo":"1.8.0.345-150200.3.24.1","java-1_8_0-openj9-devel":"1.8.0.345-150200.3.24.1","java-1_8_0-openj9-headless":"1.8.0.345-150200.3.24.1","java-1_8_0-openj9-javadoc":"1.8.0.345-150200.3.24.1","java-1_8_0-openj9-src":"1.8.0.345-150200.3.24.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3092-1.json"}},{"package":{"name":"java-1_8_0-openj9","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/java-1_8_0-openj9&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0.345-150200.3.24.1"}]}],"ecosystem_specific":{"binaries":[{"java-1_8_0-openj9":"1.8.0.345-150200.3.24.1","java-1_8_0-openj9-accessibility":"1.8.0.345-150200.3.24.1","java-1_8_0-openj9-demo":"1.8.0.345-150200.3.24.1","java-1_8_0-openj9-devel":"1.8.0.345-150200.3.24.1","java-1_8_0-openj9-headless":"1.8.0.345-150200.3.24.1","java-1_8_0-openj9-javadoc":"1.8.0.345-150200.3.24.1","java-1_8_0-openj9-src":"1.8.0.345-150200.3.24.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3092-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223092-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198671"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198672"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198673"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198674"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198675"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198935"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201684"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201692"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201694"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-41041"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21426"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21434"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21443"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21476"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21496"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21540"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21541"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-34169"}]}