PT-2025-29601 · Oracle+10 · Oracle Java Se+13

Published

2025-07-15

·

Updated

2026-05-08

·

CVE-2025-30749

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions prior to 8u451 Oracle GraalVM for JDK versions prior to 17.0.15 Oracle GraalVM Enterprise Edition versions prior to 21.3.14 Oracle Java SE versions 11.0.27 Oracle Java SE versions 17.0.15 Oracle Java SE versions 21.0.7 Oracle Java SE versions 24.0.1 Oracle GraalVM for JDK versions 17.0.15 Oracle GraalVM for JDK versions 21.0.7 Oracle GraalVM for JDK versions 24.0.1 Oracle GraalVM Enterprise Edition versions 21.3.14
Description This issue affects Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. It is a difficult-to-exploit vulnerability that allows an unauthenticated attacker with network access via multiple protocols to compromise the affected products. Successful attacks can result in a complete system takeover. This vulnerability applies to Java deployments that load and run untrusted code, such as sandboxed Java Web Start applications or Java applets. It does not apply to deployments that run only trusted code.
Recommendations Update Oracle Java SE to a version later than 8u451. Update Oracle GraalVM for JDK to a version later than 17.0.15. Update Oracle GraalVM Enterprise Edition to a version later than 21.3.14. Update Oracle Java SE to a version later than 11.0.27. Update Oracle Java SE to a version later than 17.0.15. Update Oracle Java SE to a version later than 21.0.7. Update Oracle Java SE to a version later than 24.0.1. Update Oracle GraalVM for JDK to a version later than 17.0.15. Update Oracle GraalVM for JDK to a version later than 21.0.7. Update Oracle GraalVM for JDK to a version later than 24.0.1. Update Oracle GraalVM Enterprise Edition to a version later than 21.3.14.

Fix

RCE

Weakness Enumeration

Related Identifiers

ALSA-2025:10862
ALSA-2025:10867
ALSA-2025:10873
ALT-PU-2025-9433
ALT-PU-2025-9439
ALT-PU-2025-9466
ALT-PU-2025-9472
ALT-PU-2025-9553
ALT-PU-2025-9565
ALT-PU-2025-9567
ALT-PU-2025-9569
ALT-PU-2025-9571
ALT-PU-2025-9573
ALT-PU-2025-9575
BDU:2025-09721
BIT-JAVA-2025-30749
BIT-JAVA-MIN-2025-30749
BIT-JRE-2025-30749
CESA-2025_10862
CESA-2025_10867
CESA-2025_10873
CESA-2025_13675
CVE-2025-30749
DLA-4248-1
DLA-4275-1
DSA-5972-1
INFSA-2025_10862
INFSA-2025_10867
INFSA-2025_10873
MGASA-2025-0233
OPENSUSE-SU-2025:15356-1
OPENSUSE-SU-2025:15357-1
OPENSUSE-SU-2025:15358-1
OPENSUSE-SU-2025:15362-1
OPENSUSE-SU-2025:15390-1
OPENSUSE-SU-2025:15391-1
OPENSUSE-SU-2025:15392-1
OPENSUSE-SU-2025:15393-1
OPENSUSE-SU-2025:15532-1
RHSA-2025:10861
RHSA-2025:10862
RHSA-2025:10865
RHSA-2025:10867
RHSA-2025:10873
RHSA-2025:13656
RHSA-2025:13675
RHSA-2025_10862
RHSA-2025_10867
RHSA-2025_10873
RHSA-2025_13675
SUSE-SU-2025:02545-1
SUSE-SU-2025:02563-1
SUSE-SU-2025:02657-1
SUSE-SU-2025:02666-1
SUSE-SU-2025:02667-1
SUSE-SU-2025:03120-1
SUSE-SU-2025:03224-1
SUSE-SU-2025:03236-1
SUSE-SU-2025:03262-1
SUSE-SU-2025_02563-1
SUSE-SU-2025_02657-1
SUSE-SU-2025_02666-1
SUSE-SU-2025_02667-1
SUSE-SU-2025_03120-1
SUSE-SU-2025_03224-1
SUSE-SU-2025_03236-1
SUSE-SU-2025_03262-1
USN-7667-1
USN-7668-1
USN-7669-1
USN-7672-1
USN-7673-1
USN-7674-1
USN-7690-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Java Platform
Linuxmint
Oracle Graalvm Enterprise Edition
Oracle Graalvm For Jdk
Oracle Java Se
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu