Impact
This vulnerability resides in the Compiler component of Oracle GraalVM and allows an attacker to compromise the system without authentication, leading to a full takeover. The flaw permits modification of confidentiality, integrity, and availability, as reflected in the CVSS vector. The description clearly states that successful exploitation can result in complete control over the GraalVM platform. The likely attack on the mention of "network access via HTTP," an unauthenticated HTTP request to the vulnerable service is inferred as the means of exploitation.
Affected Systems
Oracle GraalVM 25.0.4.1 is the only documented affected version. Administrators should verify whether their installations match this version and apply any available updates thereafter.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity with full impact on confidentiality, integrity, and availability. The EPSS score of less than 1% suggests that, as of the most recent data, the probability of exploitation is low, and the vulnerability is not listed in CISA's KEV catalog. Nevertheless, because the flaw permits a remote takeover, the potential impact remains significant, warranting timely remediation.
OpenCVE Enrichment