Java SE and GraalVM Enterprise Edition Vulnerability in Oracle Products
CVE-2024-21003
Summary
A vulnerability exists in Oracle Java SE and GraalVM Enterprise Edition that allows an unauthenticated attacker with network access via multiple protocols to potentially compromise affected systems. Exploitation requires human interaction from a user other than the attacker. Successful exploitation could lead to unauthorized updates, inserts, or deletions of accessible data in environments where untrusted code is loaded, such as sandboxed Java Web Start applications or applets. This vulnerability poses risks in client-side deployments but does not impact server environments running only trusted code.
Affected Version(s)
Java SE JDK and JRE Oracle Java SE:8u401
Java SE JDK and JRE Oracle GraalVM Enterprise Edition:20.3.13
Java SE JDK and JRE Oracle GraalVM Enterprise Edition:21.3.9
References
CVSS V3.1
Timeline
Vulnerability published