Impact
A flaw in the Oracle GraalVM compiler component enables an attacker with network access over HTTP to exploit Oracle GraalVM without authentication. The vulnerability is rooted in an lack of proper authorization checks, classified as CWE-284, and can lead to a full compromise of the GraalVM instance, affecting confidentiality, integrity, and availability.
Affected Systems
Oracle GraalVM, version 25.0.4.1. No other versions are listed in the advisory; the vulnerability does not affect earlier or later releases unless explicitly stated by Oracle.
Risk and Exploitability
The CVSS v3.1 base score is 8.1, indicating high severity. The EPSS score is below 1%, suggesting that while exploitation is technically feasible, it is unlikely to be widely deployed. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to send malicious HTTP requests to the GraalVM instance; no prior authentication or elevated privileges are required, but the attack complexity is high due to the need to trigger the specific compiler behavior.
OpenCVE Enrichment