Vulnerability in Oracle Java SE and GraalVM Products by Oracle
CVE-2025-61748

3.7LOW

What is CVE-2025-61748?

A vulnerability exists in Oracle Java SE and GraalVM products allowing unauthenticated attackers with network access to exploit the system. This can lead to unauthorized updates, inserts, or deletions of data. The affected products include multiple versions of Oracle Java SE and GraalVM that support operation through various protocols. Exploitation may involve APIs in the specified component; for instance, an attacker might leverage a web service that feeds data into these APIs. Additionally, this vulnerability impacts Java deployments with sandboxed environments where untrusted code is executed, posing a significant risk to secure application environments.

Affected Version(s)

Oracle GraalVM Enterprise Edition 21.3.15

Oracle GraalVM for JDK 21.0.8

Oracle Java SE 21.0.8

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.