Vulnerability in Oracle Java SE and GraalVM Products
CVE-2025-21587

7.4HIGH

Key Information:

Summary

This vulnerability in Oracle Java SE and GraalVM components allows attackers to exploit unauthenticated network access, potentially leading to unauthorized control over critical data. Attackers can manipulate Java environments, particularly those using sandboxed applications, enabling them to create, delete, or modify sensitive information. The vulnerability is particularly concerning for deployments running untrusted code via APIs, which may expose critical weaknesses across multiple protocols.

Affected Version(s)

Oracle GraalVM Enterprise Edition 20.3.17

Oracle GraalVM Enterprise Edition 21.3.13

Oracle GraalVM for JDK 17.0.14

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.