Junglewise Threat Intelligence

CVE-2025-61748: Oracle Java SE and GraalVM improper access control in Libraries

CVE-2025-61748 · Severity: low · CVSS 3.7 · Published 2025-10-21

Technologies: Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle Graalvm For Jdk, Siemens SIMATIC CN 4100. Vendors: Oracle, Siemens.

Executive brief

A vulnerability exists in the core libraries of Oracle Java and GraalVM, which are widely used to run enterprise applications and web services. An attacker could potentially modify or delete certain data within the application's environment. While the flaw is difficult to exploit, it poses a risk to systems that process untrusted data or run sandboxed applications, such as those used in industrial communication nodes like Siemens SIMATIC CN 4100.

Technical details

An improper access control vulnerability (CWE-284) exists in the Libraries component of Oracle Java SE and GraalVM. The flaw is characterized by a high attack complexity, requiring specific conditions to be met for successful exploitation. An unauthenticated attacker with network access via multiple protocols can exploit this through APIs, such as web services that supply data to the affected component. The vulnerability also impacts Java sandboxing mechanisms, potentially allowing untrusted code (e.g., from Java Web Start or applets) to bypass integrity protections. Successful exploitation results in unauthorized update, insert, or delete access to accessible data. Oracle addressed this in the October 2025 Critical Patch Update, and Siemens has released SIMATIC CN 4100 V5.0 to mitigate the downstream impact.

Affected products

  • Oracle Java SE 21.0.8, 25
  • Oracle GraalVM for JDK 21.0.8
  • Oracle GraalVM Enterprise Edition 21.3.15
  • Siemens SIMATIC CN 4100 All versions < V5.0

Timeline

  • 2025-10-21: disclosed: Initial disclosure by Oracle
  • 2025-10-21: advisory: Oracle October 2025 Critical Patch Update released
  • 2026-05-12: patched: Siemens released SIMATIC CN 4100 V5.0 to address the vulnerability in downstream products

References

Related threats