Authentication Bypass in Oracle Java SE and GraalVM Products
CVE-2024-21131

3.7LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 July 2024

Summary

A vulnerability in Oracle Java SE and GraalVM components allows unauthenticated attackers with network access to compromise the affected products. With this issue, attackers can potentially gain unauthorized access to sensitive data, manipulate or delete it through accessible APIs. This threat extends to Java environments running sandboxed applications that may load untrusted code. Organizations using these products should update to secure versions immediately to protect against potential exploitation.

Affected Version(s)

Java SE JDK and JRE Oracle Java SE:8u411

Java SE JDK and JRE Oracle Java SE:8u411-perf

Java SE JDK and JRE Oracle Java SE:11.0.23

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.