CVE-2024-21098

CVSS 3.1 Score 3.7 of 10 (low)

Details

Published Apr 16, 2024
Updated: Apr 17, 2024

Summary

CVE-2024-21098 is a vulnerability affecting Oracle GraalVM for JDK (versions: 17.0.10, 21.0.2, 22) and Oracle GraalVM Enterprise Edition (versions: 20.3.13, 21.3.9). This issue lies in the Oracle Java SE component's Compiler and can be exploited by unauthenticated attackers with network access using multiple protocols. Successful exploitation may result in a partial denial of service (DOS) for Oracle GraalVM for JDK and Oracle GraalVM Enterprise Edition. With a base score of 3.7 in terms of availability impact, this vulnerability is considered difficult to exploit but still poses a potential threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share