Lucene search

K
redosRedosROS-20240730-14
HistoryJul 30, 2024 - 12:00 a.m.

ROS-20240730-14

2024-07-3000:00:00
redos.red-soft.ru
6
oracle java se
graalvm
vulnerability
insufficient input validation
data protection
confidentiality
integrity
availability

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

6.6

Confidence

Low

A vulnerability in the Hotspot component of the Oracle Java SE software platform and Oracle GraalVM virtual machines
for JDK and Oracle GraalVM Enterprise Edition virtual machines is related to the lack of service data protection. Exploitation
exploitation of the vulnerability could allow an attacker acting remotely to gain access to confidential
information

Vulnerability in the Hotspot component of Oracle GraalVM Enterprise Edition virtual machines, Oracle GraalVM for
JDK and Oracle Java SE software platform is related to insufficient input validation.
Exploitation of the vulnerability could allow an attacker acting remotely to gain read access,
modify, or delete data

Vulnerability in the Hotspot component of the Oracle Java SE software platform and Oracle GraalVM virtual machines.
for JDK and Oracle GraalVM Enterprise Edition exists due to insufficient input validation.
Exploitation of the vulnerability could allow an attacker acting remotely to impact the
data integrity

Vulnerability in the Security component of the Oracle Java SE software platform, Oracle GraalVM Virtual Machines
for JDK and Oracle GraalVM Enterprise Edition virtual machines exists due to insufficient input validation.
Exploitation of the vulnerability could allow an attacker acting remotely to impact the
Confidentiality, integrity, and availability of protected information

Vulnerability in the Security component of the Oracle Java SE software platform and Oracle GraalVM virtual machines.
for JDK and Oracle GraalVM Enterprise Edition exists due to insufficient input validation.
Exploitation of the vulnerability could allow an attacker to gain access to sensitive information

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64java-1.8.0-openjdk< 1.8.0.402.b06-3UNKNOWN

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

6.6

Confidence

Low