Impact
Improper validation of certificates during security checks (CWE‑295) combined with an access control weakness (CWE‑284) allows an attacker to send specially crafted data to Java security APIs and bypass certificate verification, enabling privileged operations. The likely attack vector is inferred as remote network access via exposed APIs, as the description mentions network reachability is sufficient for exploitation and no authentication is required.
Affected Systems
Affected products include Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. Vulnerable versions are 8u491 and 8u491‑perf for Java SE, 11.0.31, 17.0.19, 21.0.11, 25.0.3, and 26.0.1 for Java SE, 17.0.19 and 21.0.11 for GraalVM for JDK, and 21.3.18 for GraalVM Enterprise Edition.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates moderate severity with low confidentiality and integrity impact. The EPSS score of less than 1 % suggests that exploitation is currently unlikely in the wild, yet the vulnerability can be triggered from any network‑reachable endpoint that exposes the compromised APIs without authentication or elevated privileges. If exploited, an attacker could modify or exfiltrate data stored by the affected Java runtime. The risk profile remains moderate, so unpatched systems should prioritize remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA