Vulnerability in Oracle GraalVM for JDK and Enterprise Edition by Oracle
CVE-2023-22091

4.8MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2023

Summary

A vulnerability exists within Oracle GraalVM for JDK and Oracle GraalVM Enterprise Edition, which can be exploited by unauthenticated attackers with network access. This exploit can lead to unauthorized operations such as updates, inserts, or deletions of data, as well as unauthorized reading of certain accessible data. The issue affects specific versions of both GraalVM for JDK and its Enterprise Edition, highlighting the importance of securing your runtime environments against potential unauthorized access.

Affected Version(s)

GraalVM Enterprise Edition Oracle GraalVM for JDK:17.0.8

GraalVM Enterprise Edition Oracle GraalVM for JDK:21

GraalVM Enterprise Edition Oracle GraalVM Enterprise Edition:20.3.11

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.