CVE-2025-50065
Published: July 18, 2025Last modified: July 20, 2025
Description
Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Native Image). The supported version that is affected is Oracle GraalVM for JDK: 24.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GraalVM for JDK. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
Severity score breakdown
Parameter | Value |
---|---|
Base score | 3.7 |
Attack Vector | NETWORK |
Attack complexity | HIGH |
Privileges required | NONE |
User interaction | NONE |
Scope | UNCHANGED |
Confidentiality | NONE |
Integrity impact | NONE |
Availability impact | LOW |
Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
Notes
CWE-269 Improper Privilege Management
Status
Product | Release | Package | Status |
---|---|---|---|
Liberica NIK | 23 (JDK 17) | core | Fixed (23.0.9+1) |
full | Fixed (23.0.9+1) | ||
standard | Fixed (23.0.9+1) | ||
23 (JDK 21) | core | Fixed (23.1.8+1) | |
full | Fixed (23.1.8+1) | ||
standard | Fixed (23.1.8+1) | ||
24 (JDK 24) | full | Fixed (24.2.2+1) | |
standard | Fixed (24.2.2+1) |