First published: Wed Apr 15 2020(Updated: )
Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: Tools). Supported versions that are affected are 19.3.1 and 20.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle GraalVM Enterprise Edition accessible data. CVSS 3.0 Base Score 3.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle GraalVM Enterprise Edition | =19.3.1 | |
Oracle GraalVM Enterprise Edition | =20.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-2900 is classified as difficult to exploit but potentially impactful if successful.
To fix CVE-2020-2900, upgrade to Oracle GraalVM 19.3.2 or later versions.
CVE-2020-2900 affects Oracle GraalVM Enterprise Edition versions 19.3.1 and 20.0.0.
CVE-2020-2900 can be exploited by low privileged attackers with network access via multiple protocols.
CVE-2020-2900 impacts the Tools component of Oracle GraalVM Enterprise Edition.