Network Vulnerability in Oracle Java SE and GraalVM Products
CVE-2025-50106

8.1HIGH

What is CVE-2025-50106?

A vulnerability exists in Oracle Java SE and GraalVM products that allows an unauthenticated attacker with network access to exploit the system. This vulnerability can be triggered through multiple protocols, potentially leading to the takeover of affected Java deployments. The flaw is related to the way untrusted code is executed in sandboxed environments, such as Java Web Start applications, exposing users to risks when utilizing APIs that handle external data. As various versions of Oracle's Java products are affected, it is crucial for users to update their systems and review security settings to mitigate potential threats.

Affected Version(s)

Oracle GraalVM Enterprise Edition 21.3.14

Oracle GraalVM for JDK 17.0.15

Oracle GraalVM for JDK 21.0.7

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.