Oracle Java SE and GraalVM 2D Component Vulnerability Allowing Takeover

Vulnerability

A vulnerability has been identified in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition, specifically within the 2D component. Affected versions include Oracle Java SE 8u451, 8u451-perf, 11.0.27, 17.0.15, 21.0.7, and 24.0.1, as well as Oracle GraalVM for JDK 17.0.15, 21.0.7, and 24.0.1. This vulnerability is difficult to exploit but allows an unauthenticated attacker with network access via multiple protocols to compromise the affected Java environments. Successful exploitation can lead to a complete takeover of the Java SE or GraalVM deployment. The vulnerability can be exploited through APIs in the 2D component, potentially via a web service that provides data to these APIs. It also affects Java deployments in clients running sandboxed Java Web Start applications or applets that load untrusted code from the internet and depend on the Java sandbox for security.

Impact

Exploitation of this vulnerability can result in a complete takeover of the affected Oracle Java SE or GraalVM environment.

Added: Jul 15, 2025, 9:07 PM
Updated: Jul 15, 2025, 9:07 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
7.5
exploitability
4.7
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.