Database Management

Database Performance Analyzer is not affected by CVE-2023-21930, CVE-2023-21937, CVE-2023-21939, CVE-2023-21954, CVE-2023-21967, and CVE-2023-21968

This article explains why DPA is not affected by CVE-2023-21930, CVE-2023-21937, CVE-2023-21939, CVE-2023-21954, CVE-2023-21967, and CVE-2023-21968.

First published date

1/12/2024 9:21 PM

Last published date

3/18/2025 2:36 PM

Overview

In November of 2023, the National Institute of Standards and Technology (NIST) updated the following security bulletins about vulnerabilities in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (various components):

  • CVE-2023-21930 Describes a vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).

  • CVE-2023-21937 Describes a vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking).

  • CVE-2023-21939 Describes a vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing).

  • CVE-2023-21954 Describes a vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot).

  • CVE-2023-21967 Describes a vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).

  • CVE-2023-21968 Describes a vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).

These vulnerabilities apply to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (for example, code that comes from the Internet) and rely on the Java sandbox for security.

These vulnerabilities can also be exploited by using APIs in the specified components (for example, through a web service that supplies data to the APIs).

Product section

Database Performance Analyzer

Cause

CVE-2023-21930, CVE-2023-21937, CVE-2023-21939, CVE-2023-21954, CVE-2023-21967, and CVE-2023-21968

Resolution

These vulnerabilities do not apply to DPA. DPA does not load untrusted code and it does not use sandboxed Java applets or Java Web Start. Also, DPA does not pass any data to components specified in the vulnerability through web services.