Azul Zulu OpenJDK is affected by multiple vulnerabilities.(2024-04-16).

Brocade Fabric OS

1 more products

24820

29 July 2024

26 July 2024

CLOSED

LOW

CVE-2023-41993, CVE-2024-21002, CVE-2024-21004, CVE-2024-21003, CVE-2024-21005, CVE-2024-21012, CVE-2024-21094, CVE-2024-21011, CVE-2024-21068, CVE-2024-21085

Brocade Security Advisory ID

BSA-2024-2658

Component

Azul Zulu OpenJDK

 

 

Summary

Azul Zulu multiple vulnerabilities as referenced in the 2024-04-16 advisory.

Affected CVEs

  • CVE-2023-41993, CVE-2024-21002, CVE-2024-21004, CVE-2024-21003, CVE-2024-21005, CVE-2024-21011, CVE-2024-21012, CVE-2024-21068, CVE-2024-21085,
  • CVE-2024-21094

CVE #

Component

Base Score

CVE-2024-21011

Hotspot

3.7

CVE-2024-21012

Networking

3.7

CVE-2024-21068

Hotspot

3.7

CVE-2024-21085

Concurrency

3.7

CVE-2023-41993 

JavaFX (WebKitGTK)

7.5

CVE-2024-21094 

Hotspot

3.7

CVE-2024-21003 

JavaFX

3.1

CVE-2024-21005 

JavaFX

3.1

CVE-2024-21002 

JavaFX

2.5

CVE-2024-21004 

JavaFX

2.5

More at: https://docs.azul.com/core/release/april-2024/release-notes

Statement for Brocade SANnav : Brocade SANnav contains the vulnerable code, but is Not Affected 

CVE #

VEX - Status Justifications

CVE-2024-21011

Vulnerable_code_cannot_be_controlled_by_adversary

CVE-2024-21012

Vulnerable_code_cannot_be_controlled_by_adversary

CVE-2024-21068

Vulnerable_code_cannot_be_controlled_by_adversary

CVE-2024-21085

Vulnerable_code_cannot_be_controlled_by_adversary

CVE-2023-41993 

Component_not_present

CVE-2024-21094 

Vulnerable_code_cannot_be_controlled_by_adversary

CVE-2024-21003 

Component_not_present

CVE-2024-21005 

Component_not_present

CVE-2024-21002 

Component_not_present

CVE-2024-21004 

Component_not_present

 

Products Confirmed Not Affected

  • Brocade Fabric OS - Not Affected - [VEX Justification: Component_not_present]
  • Brocade ASCG - Not Affected - [VEX Justification: Component_not_present]

Solution

Brocade SANnav is Not Affected, however, Brocade will provide the Azul Zulu April 2024 update in the upcoming SANnav 2.4.0 and 2.3.1b releases

Revision History

Version

Change

Date

1.0

Initial Publication

7/26/2024

1.1

update the last CVE in the Affected CVE CVE-2024-21085

7/29/2024

 

Disclaimer

THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.