Unauthorized Access Vulnerability in Oracle GraalVM Enterprise Edition
CVE-2020-2595

5.8MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 January 2020

Summary

An exploitable vulnerability exists in the GraalVM Compiler component of Oracle's GraalVM Enterprise Edition that allows unauthenticated attackers with network access through multiple protocols to gain unauthorized read access to sensitive data. While the primary impact is within the Oracle GraalVM Enterprise Edition, it can potentially affect other products relying on it. This situation creates significant risks for organizations utilizing Oracle GraalVM Enterprise Edition in their operations.

Affected Version(s)

GraalVM Enterprise Edition 19.3.0.2

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.