PT-2024-1160 · Oracle+10 · Graalvm For Jdk+13

Valentin Eudeline

·

Published

2024-01-16

·

Updated

2026-05-08

·

CVE-2024-20926

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 8u391, 8u391-perf, 11.0.21 Oracle GraalVM for JDK version 17.0.9 Oracle GraalVM Enterprise Edition versions 20.3.12, 21.3.8, 22.3.4
Description The issue is related to insufficient input validation in the Scripting component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. This vulnerability can be exploited by an unauthenticated attacker with network access via multiple protocols, allowing them to compromise the affected systems. Successful attacks can result in unauthorized access to critical data or complete access to all accessible data. The vulnerability can be exploited using APIs in the specified component, for example, through a web service that supplies data to the APIs. It also applies to Java deployments that load and run untrusted code and rely on the Java sandbox for security.
Recommendations For Oracle Java SE versions 8u391, 8u391-perf, 11.0.21, update to a version that includes the fix for this vulnerability. For Oracle GraalVM for JDK version 17.0.9, update to a version that includes the fix for this vulnerability. For Oracle GraalVM Enterprise Edition versions 20.3.12, 21.3.8, 22.3.4, update to a version that includes the fix for this vulnerability. As a temporary workaround, consider restricting access to the Scripting component and limiting the use of APIs that can be exploited.

Exploit

Fix

Protection Mechanism Failure

Deserialization of Untrusted Data

RCE

Improper Access Control

Weakness Enumeration

Related Identifiers

ALSA-2024:0265
ALSA-2024:0266
ALT-PU-2024-17577
ALT-PU-2024-17585
ALT-PU-2024-17587
ALT-PU-2024-17589
ALT-PU-2024-17592
ALT-PU-2024-17593
ALT-PU-2025-1037
ALT-PU-2025-6317
BDU:2024-00484
BIT-JAVA-2024-20926
BIT-JAVA-MIN-2024-20926
BIT-JRE-2024-20926
CESA-2024_0223
CESA-2024_0232
CESA-2024_0265
CESA-2024_0266
CESA-2024_1481
CVE-2024-20926
DLA-3728-1
DSA-5604-1
DSA-5613-1
MGASA-2024-0061
OESA-2024-1099
OESA-2024-1127
OESA-2024-1149
OESA-2024-1150
OESA-2024-1152
OESA-2024-1153
OESA-2024-1154
OESA-2024-2485
OESA-2024-2486
OESA-2024-2487
OESA-2024-2488
OESA-2024-2489
OPENSUSE-SU-2024:13602-1
OPENSUSE-SU-2024:13654-1
OPENSUSE-SU-2024_0479-1
OPENSUSE-SU-2024_0847-1
OPENSUSE-SU-2025:0066-1
RHSA-2024:0223
RHSA-2024:0224
RHSA-2024:0225
RHSA-2024:0226
RHSA-2024:0228
RHSA-2024:0232
RHSA-2024:0233
RHSA-2024:0234
RHSA-2024:0235
RHSA-2024:0237
RHSA-2024:0265
RHSA-2024:0266
RHSA-2024:1481
RHSA-2024:1482
RHSA-2024_0223
RHSA-2024_0232
RHSA-2024_0265
RHSA-2024_0266
RHSA-2024_1481
RHSA-2024_1482
ROSA-SA-2024-2480
ROSA-SA-2024-2481
SUSE-SU-2024:0203-1
SUSE-SU-2024:0321-1
SUSE-SU-2024:0479-1
SUSE-SU-2024:0605-1
SUSE-SU-2024:0619-1
SUSE-SU-2024:0804-1
SUSE-SU-2024:0847-1
USN-6660-1
USN-6696-1
USN-7096-1
USN-7096-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Graalvm Enterprise Edition
Graalvm For Jdk
Ibm Aix
Java Platform
Java Se
Linuxmint
Red Hat
Red Os
Suse
Ubuntu