CVE-2025-50059

8.6

Oracle · Java SE, GraalVM for JDK, and GraalVM Enterprise Edition

An unauthenticated, remotely exploitable vulnerability in the Networking component of Oracle Java SE and GraalVM allows for unauthorized access to sensitive data via multiple protocols.

Executive summary

A critical vulnerability in Oracle Java SE and GraalVM allows unauthenticated remote attackers to bypass security controls and access sensitive data, potentially impacting the entire system scope.

Vulnerability

This is a networking-based vulnerability that allows an unauthenticated attacker to bypass the Java sandbox, leading to unauthorized access to critical data. The flaw is easily exploitable over the network and permits cross-protocol attacks.

Business impact

The vulnerability carries a CVSS score of 8.6, reflecting its high severity due to the lack of required authentication and the potential for complete data compromise. Successful exploitation could lead to significant unauthorized access to proprietary or customer data, resulting in severe reputational damage, regulatory non-compliance, and potential loss of intellectual property.

Remediation

Immediate Action: Update all affected installations of Oracle Java SE and GraalVM to the versions specified in the July 2025 Oracle Critical Patch Update.

Proactive Monitoring: Review application access logs for unusual network traffic patterns or unauthorized requests directed at Java-based services.

Compensating Controls: Deploy network-level access controls or Web Application Firewalls (WAF) to restrict access to Java-based services from untrusted networks, particularly for environments running sandboxed applets.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the ease of exploitability and the potential for unauthorized data access, organizations should treat this vulnerability as a high-priority update. Administrators must verify their current Java runtime environments against the listed affected versions and apply the Oracle July 2025 security patches immediately to eliminate the exposure risk.

More Oracle CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Published in the daily brief high section
  4. Analyst report written

Sources