Database Management
Database Performance Analyzer is not affected by CVE-2023-21930, CVE-2023-21937, CVE-2023-21939, CVE-2023-21954, CVE-2023-21967, and CVE-2023-21968
This article explains why DPA is not affected by CVE-2023-21930, CVE-2023-21937, CVE-2023-21939, CVE-2023-21954, CVE-2023-21967, and CVE-2023-21968.
First published date
Last published date
Overview
In November of 2023, the National Institute of Standards and Technology (NIST) updated the following security bulletins about vulnerabilities in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (various components):
-
CVE-2023-21930 Describes a vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).
-
CVE-2023-21937 Describes a vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking).
-
CVE-2023-21939 Describes a vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing).
-
CVE-2023-21954 Describes a vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot).
-
CVE-2023-21967 Describes a vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).
-
CVE-2023-21968 Describes a vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).
These vulnerabilities apply to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (for example, code that comes from the Internet) and rely on the Java sandbox for security.
These vulnerabilities can also be exploited by using APIs in the specified components (for example, through a web service that supplies data to the APIs).
Product section
Cause
CVE-2023-21930, CVE-2023-21937, CVE-2023-21939, CVE-2023-21954, CVE-2023-21967, and CVE-2023-21968
Resolution
These vulnerabilities do not apply to DPA. DPA does not load untrusted code and it does not use sandboxed Java applets or Java Web Start. Also, DPA does not pass any data to components specified in the vulnerability through web services.