Denial of Service Vulnerability in Oracle GraalVM Enterprise Edition
CVE-2019-2986

7.7HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 October 2019

Summary

A vulnerability exists in the Oracle GraalVM Enterprise Edition, specifically in the LLVM Interpreter component, that allows a low privileged attacker with network access to exploit the system. This flaw can lead to significant disruptions, including the potential for repeated crashes or hangs of the affected product. The vulnerability impacts not only Oracle GraalVM Enterprise Edition but could also affect other products due to its system-level nature. Attackers using various network protocols can leverage this vulnerability, making it imperative for users to apply appropriate patches to mitigate risks and maintain service availability.

Affected Version(s)

GraalVM Enterprise Edition 19.2.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.