Vulnerability in Oracle GraalVM Enterprise Edition Tools
CVE-2020-2900

3.7LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

A vulnerability exists in Oracle GraalVM Enterprise Edition related to the Tools component, affecting versions 19.3.1 and 20.0.0. This vulnerability permits a low-privileged attacker with network access to potentially compromise the software by exploiting human interaction from a third party. Successful exploitation might result in unauthorized modifications—including updates, inserts, and deletions of accessible data—along with unauthorized read access to certain sensitive data within the Oracle GraalVM Enterprise Edition ecosystem.

Affected Version(s)

GraalVM Enterprise Edition 19.3.1

GraalVM Enterprise Edition 20.0.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.