Vulnerability in Oracle Java SE and GraalVM Products
CVE-2024-21011

3.7LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 April 2024

Summary

A vulnerability exists in Oracle Java SE and GraalVM that enables unauthenticated attackers with network access to exploit multiple protocols, potentially leading to partial denial of service. This risk is particularly critical for Java deployments that utilize sandboxed applications or applets. Attackers can leverage APIs within these components to execute untrusted code, impacting system availability without compromising security features.

Affected Version(s)

Java SE JDK and JRE Oracle Java SE:8u401

Java SE JDK and JRE Oracle Java SE:8u401-perf

Java SE JDK and JRE Oracle Java SE:11.0.22

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.