Vulnerability in Oracle GraalVM Compiler Affecting Oracle GraalVM Enterprise Edition
CVE-2020-2799

6.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

A vulnerability exists in the GraalVM Compiler of Oracle GraalVM Enterprise Edition, affecting versions 19.3.1 and 20.0.0. This vulnerability allows a low-privileged attacker with network access to exploit the system through multiple protocols. While the primary target is the Oracle GraalVM Enterprise Edition, the ramifications of successful attacks can significantly affect other connected systems. This vulnerability may enable unauthorized creation, deletion, or modification of critical data, leading to severe integrity impacts on all accessible data within the affected product.

Affected Version(s)

GraalVM Enterprise Edition 19.3.1

GraalVM Enterprise Edition 20.0.0

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.