Oracle Java SE
cpe:2.3:a:oracle:java_se:*:*:*:*:*:*:*, +1 more
- 8u431-perf
- 11.0.25
- 17.0.13
- 21.0.5
- 23.0.1
A vulnerability has been identified in multiple versions of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. This vulnerability, which affects the Hotspot component, allows an unauthenticated attacker with network access to compromise the Java runtime. Successful exploitation can lead to unauthorized read access and the ability to update, insert, or delete certain accessible data. The vulnerability can be exploited through APIs, potentially via a web service, and also impacts Java deployments that run untrusted code from the internet, relying on the Java sandbox for security.
Exploitation of this vulnerability can result in unauthorized access to read, modify, or delete certain data within the affected Java runtime environments.
Users can upgrade to the latest versions of OpenJDK 11 or OpenJDK 17. For Oracle products, refer to the Oracle January 2025 Critical Patch Update. NetApp products affected by this vulnerability can be updated according to the guidance provided in the NetApp advisory NTAP-20250124-0009.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.