Impact
A security flaw in the Oracle GraalVM compiler component allows an unauthenticated attacker who can reach the system over HTTP to gain unauthorized access to sensitive data and perform limited write operations. The impact includes the possibility of partial denial of service, as well as the ability to read, modify, or delete data within the GraalVM ecosystem. The vulnerability is rated moderate, with significant confidentiality impact but lower integrity and availability effects as reflected in its CVSS vector.
Affected Systems
Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, and Oracle Graal are 23.0.13.1 for GraalVM for JDK on JDK 17, 23.1.12.1 for GraalVM for JDK on JDK 21, 21.3.19.1 for Oracle GraalVM Enterprise Edition, and 25.0.4.1 for the standard Oracle GraalVM. Proprietary GraalVM products that include the same compiler component are also at risk.
Risk and Exploitability
The CVSS score of 7.0 indicates a moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. Because the vulnerability is accessible via standard HTTP and requires no authentication, it remains a significant threat if an attacker can over the network, even though it is not yet included in CISA’s KEV catalog.
OpenCVE Enrichment