Vulnerability in Oracle Java SE and GraalVM Products Exploitable by Unauthenticated Attackers
CVE-2024-21211
3.7LOW
Summary
A vulnerability exists in Oracle's Java SE and GraalVM products that allows unauthenticated attackers with network access through various protocols to compromise system integrity. Successful exploitation could enable unauthorized updates, inserts, or deletions of data accessible through these platforms. The vulnerability poses a risk particularly in Java deployments utilizing sandboxed environments for running untrusted code, such as Java Web Start applications or applets. Developers and administrators should review and mitigate potential impacts following Oracle's advisory.
Affected Version(s)
GraalVM Oracle Java SE:23
GraalVM Oracle GraalVM for JDK:17.0.12
GraalVM Oracle GraalVM for JDK:21.0.4
References
CVSS V3.1
Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved