Vulnerability in Oracle Java SE and GraalVM Products
CVE-2024-20919
5.9MEDIUM
Summary
A vulnerability exists in Oracle Java SE and GraalVM products that allows unauthorized access and manipulation of critical data. Unauthenticated attackers can exploit this weakness over a network by sending crafted data to specific APIs in the Hotspot component. Affected versions of Oracle Java SE and Oracle GraalVM could lead to unauthorized creation, deletion, or modification of data. The risk is particularly pronounced as exploitation does not require untrusted Java applications, potentially affecting all accessible data within these environments.
Affected Version(s)
Java SE JDK and JRE Oracle Java SE:8u391
Java SE JDK and JRE Oracle Java SE:8u391-perf
Java SE JDK and JRE Oracle Java SE:11.0.21
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved