Oracle Java SE and GraalVM Enterprise Edition Scripting Component Vulnerability Allowing Unauthorized Data Modification

Vulnerability

A vulnerability has been identified in the Oracle Java SE and Oracle GraalVM Enterprise Edition products, specifically in the Scripting component. Affected versions include Oracle Java SE 8u451, 8u451-perf, and 11.0.27, as well as Oracle GraalVM Enterprise Edition 21.3.14. This vulnerability, which is difficult to exploit, allows an unauthenticated attacker with network access via multiple protocols to compromise the affected Java environments. Successful exploitation could lead to unauthorized creation, deletion, or modification of critical data, or any data accessible within the Oracle Java SE or GraalVM Enterprise Edition environments. The vulnerability can be exploited through APIs in the Scripting component, such as via a web service that provides data to these APIs. It also affects Java deployments in clients running sandboxed Java Web Start applications or applets that load untrusted code from the internet and depend on the Java sandbox for security.

Impact

Exploitation of this vulnerability could result in unauthorized changes to critical data or any data accessible within the affected Oracle Java SE or GraalVM Enterprise Edition environments.

Added: Jul 16, 2025, 12:01 AM
Updated: Jul 16, 2025, 12:01 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.7
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.