PT-2024-4349 · Oracle+1 · Oracle Graalvm Enterprise Edition+2

Published

2024-04-16

·

Updated

2024-12-06

·

CVE-2024-21098

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Oracle GraalVM for JDK versions 17.0.10, 21.0.2, 22 Oracle GraalVM Enterprise Edition versions 20.3.13, 21.3.9
Description The issue is related to a vulnerability in the Compiler component of Oracle GraalVM for JDK and Oracle GraalVM Enterprise Edition. This vulnerability allows an unauthenticated attacker with network access via multiple protocols to compromise the system. Successful attacks can result in a partial denial of service (partial DOS) of Oracle GraalVM for JDK and Oracle GraalVM Enterprise Edition.
Recommendations For Oracle GraalVM for JDK versions 17.0.10, 21.0.2, 22, update to a version that includes the fix for this issue. For Oracle GraalVM Enterprise Edition versions 20.3.13, 21.3.9, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting network access to the affected systems to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04838
CVE-2024-21098
RHSA-2024:4079
RHSA-2024:4081

Affected Products

Oracle Graalvm Enterprise Edition
Oracle Graalvm For Jdk
Red Os