Scripting Vulnerability in Oracle Java SE and GraalVM Enterprise Edition
CVE-2025-30761

5.9MEDIUM

What is CVE-2025-30761?

A vulnerability in Oracle Java SE and Oracle GraalVM Enterprise Edition allows unauthenticated attackers with network access to exploit the scripting component. The flaw enables unauthorized actions, including the creation, deletion, or modification of critical data. This vulnerability is particularly concerning as it affects Java applications that rely on a sandbox for security, potentially allowing untrusted code to execute. Attackers can leverage certain APIs to access the vulnerable component, making it essential for users to secure their Oracle installations.

Affected Version(s)

Oracle GraalVM Enterprise Edition 21.3.14

Oracle Java SE 8u451

Oracle Java SE 8u451-perf

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-30761 : Scripting Vulnerability in Oracle Java SE and GraalVM Enterprise Edition