Vulnerability in Oracle Java SE and GraalVM Products
CVE-2025-21587
7.4HIGH
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 15 April 2025
What is CVE-2025-21587?
This vulnerability in Oracle Java SE and GraalVM components allows attackers to exploit unauthenticated network access, potentially leading to unauthorized control over critical data. Attackers can manipulate Java environments, particularly those using sandboxed applications, enabling them to create, delete, or modify sensitive information. The vulnerability is particularly concerning for deployments running untrusted code via APIs, which may expose critical weaknesses across multiple protocols.
Affected Version(s)
Oracle GraalVM Enterprise Edition 20.3.17
Oracle GraalVM Enterprise Edition 21.3.13
Oracle GraalVM for JDK 17.0.14