Lucene search

K
vulnrichmentOracleVULNRICHMENT:CVE-2024-21147
HistoryJul 16, 2024 - 10:39 p.m.

CVE-2024-21147

2024-07-1622:39:59
oracle
github.com
34
security
vulnerability
2024

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

CNA Affected

[
  {
    "vendor": "Oracle Corporation",
    "product": "Java SE JDK and JRE",
    "versions": [
      {
        "status": "affected",
        "version": "Oracle Java SE:8u411"
      },
      {
        "status": "affected",
        "version": "Oracle Java SE:8u411-perf"
      },
      {
        "status": "affected",
        "version": "Oracle Java SE:11.0.23"
      },
      {
        "status": "affected",
        "version": "Oracle Java SE:17.0.11"
      },
      {
        "status": "affected",
        "version": "Oracle Java SE:21.0.3"
      },
      {
        "status": "affected",
        "version": "Oracle Java SE:22.0.1"
      },
      {
        "status": "affected",
        "version": "Oracle GraalVM for JDK:17.0.11"
      },
      {
        "status": "affected",
        "version": "Oracle GraalVM for JDK:21.0.3"
      },
      {
        "status": "affected",
        "version": "Oracle GraalVM for JDK:22.0.1"
      },
      {
        "status": "affected",
        "version": "Oracle GraalVM Enterprise Edition:20.3.14"
      },
      {
        "status": "affected",
        "version": "Oracle GraalVM Enterprise Edition:21.3.10"
      }
    ]
  }
]

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:oracle:java_se:*:*:*:*:*:*:*:*"
    ],
    "vendor": "oracle",
    "product": "java_se",
    "versions": [
      {
        "status": "affected",
        "version": "8u411"
      },
      {
        "status": "affected",
        "version": "8u411-perf"
      },
      {
        "status": "affected",
        "version": "11.0.23"
      },
      {
        "status": "affected",
        "version": "17.0.11"
      },
      {
        "status": "affected",
        "version": "21.0.3"
      },
      {
        "status": "affected",
        "version": "22.0.1"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:a:oracle:graalvm_for_jdk:*:*:*:*:*:*:*:*"
    ],
    "vendor": "oracle",
    "product": "graalvm_for_jdk",
    "versions": [
      {
        "status": "affected",
        "version": "17.0.11"
      },
      {
        "status": "affected",
        "version": "21.0.3"
      },
      {
        "status": "affected",
        "version": "22.0.1"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:a:oracle:graalvm_enterprise_edition:*:*:*:*:*:*:*:*"
    ],
    "vendor": "oracle",
    "product": "graalvm_enterprise_edition",
    "versions": [
      {
        "status": "affected",
        "version": "20.3.14"
      },
      {
        "status": "affected",
        "version": "21.3.10"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

total