CVE-2020-2799

MEDIUM

Oracle GraalVM Enterprise Edition 19.3.1 and 20.0.0 - Unauthorized Data Modification via GraalVM Compiler

Title source: llm
STIX 2.1

Description

Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: GraalVM Compiler). Supported versions that are affected are 19.3.1 and 20.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle GraalVM Enterprise Edition accessible data. CVSS 3.0 Base Score 6.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N).

References (1)

Core 1
Core References

Scores

CVSS v3 6.3
EPSS 0.0092
EPSS Percentile 56.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (2)
oracle/graalvm 19.3.1
oracle/graalvm 20.0.0
Published Apr 15, 2020
Tracked Since Feb 18, 2026