Oracle Java SE and GraalVM 2D Component Vulnerability Allowing Takeover via Network Access

Vulnerability

A vulnerability has been identified in the 2D component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. Affected versions include Oracle Java SE 8u451, 8u451-perf, 11.0.27, 17.0.15, 21.0.7, and 24.0.1; Oracle GraalVM for JDK 17.0.15, 21.0.7, and 24.0.1; and Oracle GraalVM Enterprise Edition 21.3.14. This vulnerability is difficult to exploit and allows an unauthenticated attacker with network access via multiple protocols to compromise the affected Java environments. Successful exploitation can lead to a complete takeover of the Java SE or GraalVM installation. The vulnerability is relevant in scenarios where untrusted code is executed, such as in sandboxed Java Web Start applications or applets, and does not affect deployments that only run trusted code.

Impact

Exploitation of this vulnerability can result in a complete takeover of the affected Oracle Java SE or GraalVM installation.

Added: Jul 15, 2025, 11:21 PM
Updated: Jul 15, 2025, 11:21 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
7.5
exploitability
4.7
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.