PT-2025-16432 · Oracle+11 · Oracle Graalvm Enterprise Edition+14

Published

2025-04-15

·

Updated

2025-09-08

·

CVE-2025-30698

CVSS v3.1

5.6

Medium

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 8u441, 8u441-perf, 11.0.26, 17.0.14, 21.0.6, 24 Oracle GraalVM for JDK versions 17.0.14, 21.0.6, 24 Oracle GraalVM Enterprise Edition versions 20.3.17, 21.3.13
Description A difficult to exploit vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition products allows an unauthenticated attacker with network access via multiple protocols to compromise these systems. Successful attacks can result in unauthorized update, insert, or delete access to some accessible data, as well as unauthorized read access to a subset of accessible data and the ability to cause a partial denial of service. This vulnerability applies to Java deployments that load and run untrusted code, such as sandboxed Java Web Start applications or sandboxed Java applets, and rely on the Java sandbox for security.
Recommendations For Oracle Java SE versions 8u441, 8u441-perf, 11.0.26, 17.0.14, 21.0.6, 24, update to a version that includes the fix for this issue. For Oracle GraalVM for JDK versions 17.0.14, 21.0.6, 24, update to a version that includes the fix for this issue. For Oracle GraalVM Enterprise Edition versions 20.3.17, 21.3.13, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to untrusted code, such as code from the internet, to minimize the risk of exploitation.

Exploit

Fix

DoS

Improper Access Control

Weakness Enumeration

Related Identifiers

ALSA-2025:3845
ALSA-2025:3852
ALSA-2025:3855
ALSA-2025:7508
ALT-PU-2025-6146
ALT-PU-2025-6150
ALT-PU-2025-6152
ALT-PU-2025-6156
ALT-PU-2025-6162
ALT-PU-2025-6172
ALT-PU-2025-6290
ALT-PU-2025-6292
ALT-PU-2025-6294
ALT-PU-2025-6300
ALT-PU-2025-6317
BDU:2025-11078
CESA-2025_3845
CESA-2025_3852
CESA-2025_3855
CESA-2025_8431
CVE-2025-30698
DLA-4173-1
DLA-4174-1
DSA-5913-1
INFSA-2025_3845
INFSA-2025_3852
INFSA-2025_3855
MGASA-2025-0156
OESA-2025-2072
OPENSUSE-SU-2025:15022-1
OPENSUSE-SU-2025:15023-1
OPENSUSE-SU-2025:15024-1
OPENSUSE-SU-2025:15053-1
OPENSUSE-SU-2025:15077-1
OPENSUSE-SU-2025:15078-1
OPENSUSE-SU-2025:15079-1
OPENSUSE-SU-2025:15080-1
OPENSUSE-SU-2025_01788-1
OPENSUSE-SU-2025_1429-1
OPENSUSE-SU-2025_1487-1
OPENSUSE-SU-2025_1490-1
OPENSUSE-SU-2025_1525-1
RHSA-2025:3844
RHSA-2025:3845
RHSA-2025:3848
RHSA-2025:3852
RHSA-2025:3855
RHSA-2025:7508
RHSA-2025:8063
RHSA-2025:8431
RHSA-2025_3845
RHSA-2025_3852
RHSA-2025_3855
RHSA-2025_8431
ROSA-SA-2025-2874
SUSE-SU-2025:01487-1
SUSE-SU-2025:01487-2
SUSE-SU-2025:01490-1
SUSE-SU-2025:01525-1
SUSE-SU-2025:01770-1
SUSE-SU-2025:01788-1
SUSE-SU-2025:01954-1
SUSE-SU-2025:1399-1
SUSE-SU-2025:1429-1
SUSE-SU-2025:1487-1
SUSE-SU-2025:1490-1
SUSE-SU-2025:1524-1
SUSE-SU-2025:1525-1
SUSE-SU-2025_01770-1
SUSE-SU-2025_01788-1
USN-7480-1
USN-7481-1
USN-7482-1
USN-7483-1
USN-7484-1
USN-7531-1
USN-7533-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Java Platform
Linuxmint
Oracle Graalvm Enterprise Edition
Oracle Graalvm For Jdk
Oracle Java Se
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu