Vulnerability in Oracle Java SE and GraalVM Products
CVE-2024-21094

3.7LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 April 2024

Summary

A security vulnerability exists within Oracle's Java SE and GraalVM products, specifically in the Hotspot component. This vulnerability permits unauthenticated attackers to exploit the systems via multiple network protocols, potentially leading to unauthorized modifications to accessible data. The affected versions of Oracle Java SE and GraalVM enable attackers to leverage APIs through web services to facilitate malicious actions. Furthermore, this vulnerability has implications for Java deployments, especially in environments using sandboxed Java Web Start applications and applets that execute untrusted code. It underscores the importance of maintaining robust security measures to protect application integrity and user data.

Affected Version(s)

Java SE JDK and JRE Oracle Java SE:8u401

Java SE JDK and JRE Oracle Java SE:8u401-perf

Java SE JDK and JRE Oracle Java SE:11.0.22

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.