DoS Vulnerability in Oracle GraalVM Enterprise Edition
CVE-2022-21634
7.5HIGH
Summary
The vulnerability in Oracle GraalVM Enterprise Edition's LLVM Interpreter component allows attackers with network access to easily compromise the system. This exploitation could lead to repeated crashes or a persistent hang of the service, effectively rendering it unavailable to legitimate users. The affected versions include 20.3.7, 21.3.3, and 22.2.0. Organizations should promptly apply the recommended updates to mitigate this risk.
Affected Version(s)
GraalVM Enterprise Edition Oracle GraalVM Enterprise Edition:20.3.7
GraalVM Enterprise Edition Oracle GraalVM Enterprise Edition:21.3.3
GraalVM Enterprise Edition Oracle GraalVM Enterprise Edition:22.2.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved