Impact
A flaw in the networking component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition permits a remote, unauthenticated attacker with HTTP access to read sensitive data or obtain full access to all data exposed by these runtimes. The vulnerability enables the attacker to bypass authorization controls. The vulnerability can affect additional products due to a scope change, raising the confidentiality impact to a complete breach of protected information.
Affected Systems
Affected are Oracle Java SE versions 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, and 26.0.2; Oracle GraalVM for JDK versions 17.0.20 and 21.0.12; and Oracle GraalVM Enterprise Edition version 21.3.19.
Risk and Exploitability
The CVSS 3.1 base score of 6.8 indicates moderate severity. With a network attack vector and high complexity, no privileges or user interaction are required, yet the scope change allows confidentiality compromise. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would likely involve crafting a malicious HTTP request to the vulnerable APIs, which can be performed by any host with network connectivity to the target.
OpenCVE Enrichment
Debian DLA
Debian DSA