Oracle GraalVM Enterprise Edition Vulnerability Exposes Systems to Remote Attacks
CVE-2020-14718

7.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 July 2020

Summary

A security vulnerability exists in the Oracle GraalVM Enterprise Edition, specifically within the JVMCI component. This flaw allows an attacker with elevated privileges to exploit the system through various network protocols. If successfully executed, the attack could lead to a complete takeover of the GraalVM instance, compromising its functionality and data integrity. Users of GraalVM, particularly those on versions 19.3.2 and 20.1.0, are strongly advised to apply available security updates to mitigate this risk.

Affected Version(s)

GraalVM Enterprise Edition 19.3.2

GraalVM Enterprise Edition 20.1.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.