Java SE and GraalVM Enterprise Edition Vulnerability in Oracle Products
CVE-2024-21003

3.1LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 April 2024

Summary

A vulnerability exists in Oracle Java SE and GraalVM Enterprise Edition that allows an unauthenticated attacker with network access via multiple protocols to potentially compromise affected systems. Exploitation requires human interaction from a user other than the attacker. Successful exploitation could lead to unauthorized updates, inserts, or deletions of accessible data in environments where untrusted code is loaded, such as sandboxed Java Web Start applications or applets. This vulnerability poses risks in client-side deployments but does not impact server environments running only trusted code.

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.