Impact
This vulnerability permits an unauthenticated attacker with network access to supply crafted data to certain APIs in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition, resulting in unauthorized read access to a subset of accessible data. The weakness involves insufficient protection of sensitive information, a classic information‑exposure flaw (CWE‑200). The impact is limited to confidentiality without affecting integrity or availability.
Affected Systems
Affected vendors include Oracle Corporation, with products Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. The specific vulnerable releases are: Oracle Java SE 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK 17.0.20 and 21.0.12; and Oracle GraalVM Enterprise Edition 21.3.19.
Risk and Exploitability
The base CVSS score is 3.7, indicating a low severity but still noteworthy confidentiality impact. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based, via multiple protocols that allow the attacker to supply malicious input to the affected APIs; an unauthenticated attacker can exploit the flaw without needing any privileged access or application‑specific features such as Java Web Start or applets.
OpenCVE Enrichment