Junglewise Threat Intelligence

CVE-2025-53057: Oracle Java SE and GraalVM improper access control in Security component

CVE-2025-53057 · Severity: medium · CVSS 5.9 · Published 2025-10-21

Technologies: Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle Graalvm For Jdk. Vendors: Oracle, Debian.

Executive brief

A security vulnerability has been identified in Oracle Java SE and GraalVM products. This flaw could allow an attacker to bypass security protections to modify or delete critical data. The risk is highest for systems that run untrusted code from the internet or web services that process external data through Java APIs.

Technical details

An improper access control vulnerability (CWE-284) exists in the Security component of Oracle Java SE and GraalVM. The flaw is difficult to exploit and requires an unauthenticated attacker to have network access via multiple protocols. Successful exploitation allows for the unauthorized creation, deletion, or modification of data accessible to the Java runtime. This vulnerability specifically impacts Java deployments that rely on the sandbox for security (such as Java Web Start or applets) and web services that expose specific Security component APIs to external data. Debian has released updates for OpenJDK 11 to address this issue.

Affected products

  • Oracle Java SE 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25
  • Oracle GraalVM for JDK 17.0.16, 21.0.8
  • Oracle GraalVM Enterprise Edition 21.3.15
  • Debian OpenJDK 11 11.0.29+6-1~deb11u1

Timeline

  • 2025-10-21: disclosed: Initial disclosure by Oracle
  • 2025-10-21: advisory: Oracle Critical Patch Update published
  • 2025-10-25: patched: Debian released security update DLA-4346-1 for OpenJDK 11

References

Related threats