CVE-2023-22041 is a difficult-to-exploit vulnerability in Oracle Java SE and GraalVM Enterprise/for JDK (Hotspot component) affecting versions 8u371-perf, 11.0.19, 17.0.7, and 20.0.1. An unauthenticated attacker with logon access to the infrastructure where these products execute can achieve unauthorized access to critical or all accessible data. This vulnerability specifically impacts client-side Java deployments running untrusted sandboxed code, not server-side deployments with trusted code. With a CVSS 3.1 Base Score of 5.1 (Medium), the attack vector is local (AV:L), but attack complexity is high (AC:H), requiring no user interaction (UI:N) and no privileges (PR:N). Successful exploitation leads to high confidentiality impact (C:H) but no integrity or availability impact. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20.3.10CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm:20.3.10:*:*:*:enterprise:*:*:* | ||
21.3.6CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm:21.3.6:*:*:*:enterprise:*:*:* | ||
22.3.2CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm:22.3.2:*:*:*:enterprise:*:*:* | ||
17.0.7CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm_for_jdk:17.0.7:*:*:*:*:*:*:* | ||
20.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm_for_jdk:20.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.