Security Vulnerability in Oracle Java SE and GraalVM Products
CVE-2025-53057

5.9MEDIUM

What is CVE-2025-53057?

A vulnerability exists within Oracle Java SE and GraalVM products, allowing unauthenticated attackers to exploit the system through various network protocols. The vulnerability can lead to unauthorized actions, including the creation, deletion, or modification of critical data. It affects both client-side Java deployments and server-side applications, particularly those that run untrusted code through APIs. This poses a significant risk as it allows attackers to bypass the security measures typically relied upon in Java applications, including sandboxed environments.

Affected Version(s)

Oracle GraalVM Enterprise Edition 21.3.15

Oracle GraalVM for JDK 17.0.16

Oracle GraalVM for JDK 21.0.8

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.