Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45219
HistoryJan 30, 2024 - 6:27 p.m.

Unauthenticated Remote Attack

2024-01-3018:27:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
oracle
java
se
graalvm
unauthenticated
remote
attack
vulnerability
multiple versions
protocols
unauthorized access
critical data

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

34.2%

Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition is vulnerable to an unauthenticated remote attack via multiple protocols. This vulnerability affects multiple versions, including Oracle Java SE 8u391, 11.0.21, 17.0.9, and 21.0.1, Oracle GraalVM for JDK 17.0.9 and 21.0.1, and Oracle GraalVM Enterprise Edition 20.3.12, 21.3.8, and 22.3.4. The vulnerability allows unauthorized access to critical data, including the creation, deletion, or modification of data.

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

34.2%