Impact
Vulnerability in the ImageIO component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition permits an unauthenticated attacker with network access to perform unauthorized update, insert, or delete operations against data accessible to the Java or GraalVM runtime. The flaw can be triggered through image processing APIs, for example from a web service that supplies JPEG data to the application, and also applies to sandboxed client deployments that load untrusted code. The impact is strictly on integrity, resulting in potential data modification without disabling services or escalating privileges. This vulnerability involves both unauthorized access control (CWE‑284) and memory corruption via out‑of‑bounds writes (CWE‑787).
Affected Systems
Oracle GraalVM Enterprise Edition 21.3.18, Oracle GraalVM for JDK 17.0.19 and 21.0.11, and Oracle Java SE 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1 are affected.
Risk and Exploitability
The CVSS v3.1 base score of 3.7 combined with an EPSS score of less than 1% indicates low severity but a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack can be carried out remotely via network protocols; no authentication or elevated privileges are required, so an attacker only needs network reach to the vulnerable system to exploit the flaw.
OpenCVE Enrichment
Debian DLA
Debian DSA