PT-2024-4881 · Oracle+11 · Java Se+13
Yakov Shafranovich
·
Published
2024-04-16
·
Updated
2026-05-08
·
CVE-2024-21085
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions:
Oracle Java SE versions 8u401, 8u401-perf, 11.0.22
Oracle GraalVM Enterprise Edition versions 20.3.13, 21.3.9
Description:
The issue is related to insufficient input validation in the Concurrency component of Oracle Java SE and Oracle GraalVM Enterprise Edition. This can be exploited by an unauthenticated attacker with network access via multiple protocols, potentially leading to a partial denial of service (DOS) of the affected systems. The vulnerability can be exploited through APIs in the specified component, for example, via a web service that supplies data to the APIs. It also affects Java deployments that load and run untrusted code from the internet and rely on the Java sandbox for security.
Recommendations:
For Oracle Java SE versions 8u401, 8u401-perf, 11.0.22, consider updating to a newer version to mitigate the risk.
For Oracle GraalVM Enterprise Edition versions 20.3.13, 21.3.9, consider updating to a newer version to mitigate the risk.
As a temporary workaround, consider restricting access to the Concurrency component until a patch is available.
Avoid using APIs in the Concurrency component that supply data from untrusted sources until the issue is resolved.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Graalvm Enterprise Edition
Ibm Aix
Java Platform
Java Se
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu