Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-15475
HistoryJan 24, 2022 - 12:00 a.m.

Oracle GraalVM Input Validation Error Vulnerability (CNVD-2022-15475)

2022-01-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
17
oracle graalvm
on-the-fly compilers
java language
oracle corporation (usa)
input validation error
serialization component
graalvm enterprise edition
remote attacker
unauthenticated
data manipulation

EPSS

0.003

Percentile

70.5%

Oracle GraalVM is a set of on-the-fly compilers written in the Java language from Oracle Corporation (USA). The product supports multiple programming languages and execution modes.GraalVM Enterprise Edition is the enterprise version of GraalVM.An input validation error vulnerability exists in Oracle GraalVM due to incorrect input validation in the serialization component of Oracle GraalVM Enterprise Edition. A remote, unauthenticated attacker could exploit this vulnerability to manipulate data.