PT-2024-1532 · Oracle+10 · Graalvm For Jdk+13

Hubert Kario

·

Published

2024-01-16

·

Updated

2026-05-08

·

CVE-2024-20952

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1 Oracle GraalVM for JDK versions 17.0.9, 21.0.1 Oracle GraalVM Enterprise Edition versions 20.3.12, 21.3.8, 22.3.4
Description A difficult to exploit vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition products allows an unauthenticated attacker with network access via multiple protocols to compromise these systems. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all accessible data, as well as unauthorized access to critical data or complete access to all accessible data. This vulnerability applies to Java deployments that load and run untrusted code and rely on the Java sandbox for security, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets.
Recommendations For Oracle Java SE versions 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1, update to a newer version that contains a fix for this vulnerability. For Oracle GraalVM for JDK versions 17.0.9, 21.0.1, update to a newer version that contains a fix for this vulnerability. For Oracle GraalVM Enterprise Edition versions 20.3.12, 21.3.8, 22.3.4, update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the Java sandbox and limiting the execution of untrusted code until a patch is available.

Exploit

Fix

Use After Free

RCE

Improper Access Control

Weakness Enumeration

Related Identifiers

ALSA-2024:0248
ALSA-2024:0249
ALSA-2024:0265
ALSA-2024:0266
ALSA-2024:0267
ALT-PU-2024-17577
ALT-PU-2024-17578
ALT-PU-2024-17579
ALT-PU-2024-17580
ALT-PU-2024-17582
ALT-PU-2024-17583
ALT-PU-2024-17585
ALT-PU-2024-17587
ALT-PU-2024-17589
ALT-PU-2024-17592
ALT-PU-2024-17593
ALT-PU-2025-1037
ALT-PU-2025-6317
BDU:2024-01064
BIT-JAVA-2024-20952
BIT-JAVA-MIN-2024-20952
BIT-JRE-2024-20952
CESA-2024_0223
CESA-2024_0232
CESA-2024_0248
CESA-2024_0265
CESA-2024_0266
CESA-2024_0267
CESA-2024_1481
CVE-2024-20952
DLA-3728-1
DSA-5604-1
DSA-5613-1
MGASA-2024-0056
MGASA-2024-0061
OESA-2024-1099
OESA-2024-1127
OESA-2024-1149
OESA-2024-1150
OESA-2024-1152
OESA-2024-1153
OESA-2024-1154
OESA-2024-2485
OESA-2024-2486
OESA-2024-2487
OESA-2024-2488
OESA-2024-2489
OPENSUSE-SU-2024:13587-1
OPENSUSE-SU-2024:13594-1
OPENSUSE-SU-2024:13602-1
OPENSUSE-SU-2024:13654-1
OPENSUSE-SU-2024_0325-1
OPENSUSE-SU-2024_0479-1
OPENSUSE-SU-2024_0847-1
OPENSUSE-SU-2025:0066-1
OPENSUSE-SU-2025:0067-1
RHSA-2024:0223
RHSA-2024:0224
RHSA-2024:0225
RHSA-2024:0226
RHSA-2024:0228
RHSA-2024:0232
RHSA-2024:0233
RHSA-2024:0234
RHSA-2024:0235
RHSA-2024:0237
RHSA-2024:0241
RHSA-2024:0242
RHSA-2024:0244
RHSA-2024:0248
RHSA-2024:0249
RHSA-2024:0265
RHSA-2024:0266
RHSA-2024:0267
RHSA-2024:1481
RHSA-2024:1482
RHSA-2024_0223
RHSA-2024_0232
RHSA-2024_0248
RHSA-2024_0249
RHSA-2024_0265
RHSA-2024_0266
RHSA-2024_0267
RHSA-2024_1481
RHSA-2024_1482
ROSA-SA-2024-2480
ROSA-SA-2024-2481
SUSE-SU-2024:0203-1
SUSE-SU-2024:0321-1
SUSE-SU-2024:0325-1
SUSE-SU-2024:0479-1
SUSE-SU-2024:0605-1
SUSE-SU-2024:0619-1
SUSE-SU-2024:0804-1
SUSE-SU-2024:0847-1
USN-6660-1
USN-6661-1
USN-6662-1
USN-6696-1
USN-7096-1
USN-7096-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Graalvm Enterprise Edition
Graalvm For Jdk
Ibm Aix
Java Platform
Java Se
Linuxmint
Red Hat
Red Os
Suse
Ubuntu