Vulnerability in Oracle Java SE and GraalVM Products by Oracle
CVE-2025-61748
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 21 October 2025
What is CVE-2025-61748?
A vulnerability exists in Oracle Java SE and GraalVM products allowing unauthenticated attackers with network access to exploit the system. This can lead to unauthorized updates, inserts, or deletions of data. The affected products include multiple versions of Oracle Java SE and GraalVM that support operation through various protocols. Exploitation may involve APIs in the specified component; for instance, an attacker might leverage a web service that feeds data into these APIs. Additionally, this vulnerability impacts Java deployments with sandboxed environments where untrusted code is executed, posing a significant risk to secure application environments.
Affected Version(s)
Oracle GraalVM Enterprise Edition 21.3.15
Oracle GraalVM for JDK 21.0.8
Oracle Java SE 21.0.8