CVE-2021-35564 is a vulnerability in the Keytool component of Oracle Java SE and Oracle GraalVM Enterprise Edition, affecting versions 7u311, 8u301, 11.0.12, 17, 20.3.3, and 21.2.0 respectively. This easily exploitable flaw allows an unauthenticated attacker with network access to compromise these products. Successful exploitation can lead to unauthorized data modification (update, insert, or delete) within accessible data, primarily impacting Java deployments running untrusted code in sandboxed environments or via specific API calls. The vulnerability has a CVSS 3.1 Base Score of 5.3 (Medium), indicating low integrity impact and no confidentiality or availability impact. Its attack vector is network-based with low attack complexity, requiring no privileges or user interaction. Currently, there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage. The EPSS score is very low, suggesting a low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20.3.3CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm:20.3.3:*:*:*:enterprise:*:*:* | ||
21.2.0CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm:21.2.0:*:*:*:enterprise:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:a:oracle:openjdk:7:update311:*:*:*:*:*:* | ||
8CPE matchmatch criteria | cpe:2.3:a:oracle:openjdk:8:update301:*:*:*:*:*:* | ||
11.0.12CPE matchmatch criteria | cpe:2.3:a:oracle:openjdk:11.0.12:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.