Impact
A security flaw in the Oracle GraalVM compiler component allows an unauthenticated attacker who can reach the system over HTTP to gain unauthorized access to sensitive data and perform limited write operations. The impact includes the possibility of partial denial of service, as well as the ability to read, modify, or delete data within the GraalVM ecosystem. The vulnerability is rated moderate, with significant confidentiality impact but lower integrity and availability effects as reflected in its CVSS vector.
Affected Systems
Oracle GraalVM for JDK (JDK 17) version 23.0.13.1, Oracle GraalVM for JDK (JDK 21) version 23.1.12.1, Oracle GraalVM Enterprise Edition version 21.3.19.1, and standard Oracle GraalVM version 25.0.4.1 are all affected.
Risk and Exploitability
The CVSS score of 7.0 indicates a moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. Because the vulnerability is accessible via standard HTTP and requires no authentication, it remains a significant threat if an attacker can reach the system over the network, even though it is not yet included in CISA’s KEV catalog.
OpenCVE Enrichment