Impact
This vulnerability permits an unauthenticated attacker who has network connectivity to supply malicious data to specific APIs in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. The flaw provides unauthorized read access to a subset of data that the Java components expose, affecting confidentiality but not integrity or availability. The weakness is an information‑exposure flaw uncovered by insufficient protection of sensitive data.
Affected Systems
Oracle Corporation’s affected products are Oracle Java SE (versions 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2), Oracle GraalVM for JDK (versions 17.0.20 and 21.0.12), and Oracle GraalVM Enterprise Edition (21.3.19). Red Hat CPE entries for OpenJDK distributions also appear in the listing, but the primary vulnerability concerns the Oracle distributions.
Risk and Exploitability
The CVSS base score of 3.7 indicates low severity, with a confidentiality impact only; the EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based: an attacker can send crafted requests over multiple protocols to the vulnerable APIs without authentication. Successful exploitation grants the attacker the ability to read information that should be protected, yet it does not allow modification or disruption of the affected systems.
OpenCVE Enrichment
Debian DLA
Debian DSA