Vulnerability in Oracle Java SE and GraalVM Products Exploitable by Unauthenticated Attackers
CVE-2024-21211

3.7LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 October 2024

Summary

A vulnerability exists in Oracle's Java SE and GraalVM products that allows unauthenticated attackers with network access through various protocols to compromise system integrity. Successful exploitation could enable unauthorized updates, inserts, or deletions of data accessible through these platforms. The vulnerability poses a risk particularly in Java deployments utilizing sandboxed environments for running untrusted code, such as Java Web Start applications or applets. Developers and administrators should review and mitigate potential impacts following Oracle's advisory.

Affected Version(s)

GraalVM Oracle Java SE:23

GraalVM Oracle GraalVM for JDK:17.0.12

GraalVM Oracle GraalVM for JDK:21.0.4

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.