Executive brief
A security vulnerability has been identified in Oracle Java SE and GraalVM products. This flaw could allow an attacker to bypass security protections to modify or delete critical data. The risk is highest for systems that run untrusted code from the internet or web services that process external data through Java APIs.
Technical details
An improper access control vulnerability (CWE-284) exists in the Security component of Oracle Java SE and GraalVM. The flaw is difficult to exploit and requires an unauthenticated attacker to have network access via multiple protocols. Successful exploitation allows for the unauthorized creation, deletion, or modification of data accessible to the Java runtime. This vulnerability specifically impacts Java deployments that rely on the sandbox for security (such as Java Web Start or applets) and web services that expose specific Security component APIs to external data. Debian has released updates for OpenJDK 11 to address this issue.
Affected products
- Oracle Java SE 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25
- Oracle GraalVM for JDK 17.0.16, 21.0.8
- Oracle GraalVM Enterprise Edition 21.3.15
- Debian OpenJDK 11 11.0.29+6-1~deb11u1
Timeline
- 2025-10-21: disclosed: Initial disclosure by Oracle
- 2025-10-21: advisory: Oracle Critical Patch Update published
- 2025-10-25: patched: Debian released security update DLA-4346-1 for OpenJDK 11