CVE-2024-20932: High severity IBM Semeru Runtime vulnerability
An unspecified vulnerability in Java SE related to the Security component could allow a remote attacker to cause high integrity impact.
Other sources
It was discovered that the Libraries component in OpenJDK failed to properly handle ZIP archives that contain a file and directory entry with the same name within the ZIP file. This could lead to integrity issues when extracting data from such archives. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
— Red Hat
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 17.0.9; Oracle GraalVM for JDK: 17.0.9; Oracle GraalVM Enterprise Edition: 21.3.8 and 22.3.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/openjdk-17to a version that resolves this vulnerability.Fixed in 17.0.12+7-2~deb11u1Fixed in 17.0.14+7-1~deb11u1Fixed in 17.0.14+7-1~deb12u1Fixed in 17.0.15+6-1~deb12u1Fixed in 17.0.15+6-1 - Upgrade
Upgrade
Oracle Java SEto a version that resolves this vulnerability.Fixed in 17.0.9 - Upgrade
Upgrade
Oracle GraalVM for JDKto a version that resolves this vulnerability.Fixed in 17.0.9 - Upgrade
Upgrade
Oracle GraalVM Enterprise Editionto a version that resolves this vulnerability.Fixed in 21.3.8 - Upgrade
Upgrade
Oracle GraalVM Enterprise Editionto a version that resolves this vulnerability.Fixed in 22.3.4
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20932?
CVE-2024-20932 has a high integrity impact, allowing remote attackers to exploit vulnerabilities in the security component of Java SE.
How do I fix CVE-2024-20932?
To address CVE-2024-20932, users should upgrade to the latest version of affected software as recommended by the vendor.
Which software is affected by CVE-2024-20932?
CVE-2024-20932 affects various versions of IBM Semeru Runtime and Oracle GraalVM Enterprise Edition, as well as specific Oracle JDK and JRE versions.
Is there a workaround for CVE-2024-20932?
Currently, there is no known workaround for CVE-2024-20932; applying the appropriate updates is advised.
When was CVE-2024-20932 discovered?
CVE-2024-20932 was disclosed as a vulnerability in January 2024.