PT-2024-1224 · Oracle+8 · Graalvm For Jdk+11

Sergey Bylokhov

+1

·

Published

2024-01-16

·

Updated

2026-05-08

·

CVE-2024-20932

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Oracle Java SE version 17.0.9 Oracle GraalVM for JDK version 17.0.9 Oracle GraalVM Enterprise Edition versions 21.3.8 and 22.3.4
Description The issue is related to insufficient input validation in the Security component of the affected software, allowing an unauthenticated attacker with network access via multiple protocols to compromise the system. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data. This vulnerability applies to Java deployments that load and run untrusted code, such as sandboxed Java Web Start applications or sandboxed Java applets, and rely on the Java sandbox for security.
Recommendations For Oracle Java SE version 17.0.9, update to a newer version that contains a fix for this vulnerability. For Oracle GraalVM for JDK version 17.0.9, update to a newer version that contains a fix for this vulnerability. For Oracle GraalVM Enterprise Edition versions 21.3.8 and 22.3.4, update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of the Security component in the affected software until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:0267
ALT-PU-2024-17578
ALT-PU-2024-17580
ALT-PU-2024-17582
ALT-PU-2024-17583
BDU:2024-00611
BIT-JAVA-2024-20932
BIT-JAVA-MIN-2024-20932
BIT-JRE-2024-20932
CESA-2024_0267
CVE-2024-20932
DSA-5613-1
MGASA-2024-0056
OESA-2024-1684
OESA-2024-1685
OESA-2024-1686
OESA-2024-1687
OESA-2024-2485
OESA-2024-2486
OESA-2024-2487
OESA-2024-2488
OESA-2024-2489
OPENSUSE-SU-2024:13587-1
OPENSUSE-SU-2024_0325-1
OPENSUSE-SU-2025:0067-1
RHSA-2024:0241
RHSA-2024:0242
RHSA-2024:0244
RHSA-2024:0267
RHSA-2024_0267
SUSE-SU-2024:0325-1
SUSE-SU-2024:0605-1
SUSE-SU-2024:0619-1
USN-6661-1

Affected Products

Alt Linux
Almalinux
Centos
Graalvm Enterprise Edition
Graalvm For Jdk
Java Platform
Java Se
Linuxmint
Red Hat
Red Os
Suse
Ubuntu