Unauthenticated Network Vulnerability in Oracle GraalVM Enterprise Edition
CVE-2019-2862

6.8MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
23 July 2019

Summary

A vulnerability exists in Oracle GraalVM Enterprise Edition that allows an unauthenticated attacker with network access through various protocols to exploit the system. This flaw could lead to unauthorized actions, including the creation, deletion, or modification of critical data within Oracle GraalVM. Notably, successful exploitation requires user interaction, thereby introducing an additional layer of complexity. The consequences of this vulnerability can extend to causing significant disruptions such as frequent system crashes or Denial of Service, impacting the availability of the affected system.

Affected Version(s)

GraalVM Enterprise Edition 19.0.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.