Azul Zulu OpenJDK is affected by multiple vulnerabilities.(2024-04-16).

Brocade Fabric OS

1 more products

24820

05 December 2024

26 July 2024

CLOSED

LOW

CVE-2023-41993, CVE-2024-21002, CVE-2024-21004, CVE-2024-21003, CVE-2024-21005, CVE-2024-21012, CVE-2024-21094, CVE-2024-21011, CVE-2024-21068, CVE-2024-21085

Brocade Security Advisory ID

BSA-2024-2658

Component

Azul Zulu OpenJDK

 

 

Summary

Azul Zulu multiple vulnerabilities as referenced in the 2024-04-16 advisory.

Affected CVEs

  • CVE-2023-41993, CVE-2024-21002, CVE-2024-21004, CVE-2024-21003, CVE-2024-21005, CVE-2024-21011, CVE-2024-21012, CVE-2024-21068, CVE-2024-21085,
  • CVE-2024-21094

CVE #

Component

Base Score

CVE-2024-21011

Hotspot

3.7

CVE-2024-21012

Networking

3.7

CVE-2024-21068

Hotspot

3.7

CVE-2024-21085

Concurrency

3.7

CVE-2023-41993

JavaFX (WebKitGTK)

7.5

CVE-2024-21094

Hotspot

3.7

CVE-2024-21003 

JavaFX

3.1

CVE-2024-21005

JavaFX

3.1

CVE-2024-21002

JavaFX

2.5

CVE-2024-21004

JavaFX

2.5

 

More at: https://docs.azul.com/core/release/april-2024/release-notes.html#fixed-issues

 

Statement for Brocade SANnav : Brocade SANnav is Not Affected 

 

CVE #

VEX - Status Justifications

CVE-2024-21011

Vulnerable_code_cannot_be_controlled_by_adversary

CVE-2024-21012

Vulnerable_code_cannot_be_controlled_by_adversary

CVE-2024-21068

Vulnerable_code_cannot_be_controlled_by_adversary

CVE-2024-21085

Vulnerable_code_cannot_be_controlled_by_adversary

CVE-2023-41993

Vulnerable_code_not_present

CVE-2024-21094

Vulnerable_code_cannot_be_controlled_by_adversary

CVE-2024-21003 

Vulnerable_code_not_present

CVE-2024-21005

Vulnerable_code_not_present

CVE-2024-21002

Vulnerable_code_not_present

CVE-2024-21004

Vulnerable_code_not_present

 

 

Products Confirmed Not Affected

  • Brocade Fabric OS - Not Affected - [VEX Justification: Component_not_present]
  • Brocade ASCG - Not Affected - [VEX Justification: Component_not_present]

Solution

Brocade SANnav is Not Affected, however, Brocade will provide the Azul Zulu April 2024 update in the upcoming SANnav 2.4.0 and 2.3.1b releases

Revision History

Version

Change

Date

1.0

Initial Publication

7/26/2024

1.1

update CVE-2024-21085

7/29/2024

2.0

updated to provide clarification note related to non applicability to AZUL Zing builds for few CVEs.

Vex Status Code updated from Component_not_present to Vulnerable_code_not_present

12/4/2024

 

Disclaimer

THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.