Scripting Vulnerability in Oracle Java SE and GraalVM Enterprise Edition
CVE-2025-30761
5.9MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 15 July 2025
What is CVE-2025-30761?
A vulnerability in Oracle Java SE and Oracle GraalVM Enterprise Edition allows unauthenticated attackers with network access to exploit the scripting component. The flaw enables unauthorized actions, including the creation, deletion, or modification of critical data. This vulnerability is particularly concerning as it affects Java applications that rely on a sandbox for security, potentially allowing untrusted code to execute. Attackers can leverage certain APIs to access the vulnerable component, making it essential for users to secure their Oracle installations.
Affected Version(s)
Oracle GraalVM Enterprise Edition 21.3.14
Oracle Java SE 8u451
Oracle Java SE 8u451-perf