Vulnerability in Oracle Java SE and GraalVM Products
CVE-2024-20919

5.9MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 February 2024

Summary

A vulnerability exists in Oracle Java SE and GraalVM products that allows unauthorized access and manipulation of critical data. Unauthenticated attackers can exploit this weakness over a network by sending crafted data to specific APIs in the Hotspot component. Affected versions of Oracle Java SE and Oracle GraalVM could lead to unauthorized creation, deletion, or modification of data. The risk is particularly pronounced as exploitation does not require untrusted Java applications, potentially affecting all accessible data within these environments.

Affected Version(s)

Java SE JDK and JRE Oracle Java SE:8u391

Java SE JDK and JRE Oracle Java SE:8u391-perf

Java SE JDK and JRE Oracle Java SE:11.0.21

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.