Miggo Logo

CVE-2025-21502:
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...

4.8

CVSS Score

Basic Information

EPSS Score
-
Published
1/21/2025
Updated
2/7/2025
KEV Status
No
Technology
-

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The provided information and fetched URL contents describe a vulnerability (CVE-2025-21502) in the 'Hotspot' component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. The description states that the vulnerability can be exploited by 'using APIs in the specified Component'. However, no specific code patches, commit details, or names of the vulnerable APIs within the Hotspot component are available. Without this information, it is not possible to identify the exact function names that would appear in a runtime profile during exploitation. The available details are too high-level to pinpoint specific vulnerable functions with confidence.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

Vuln*r**ility in t** Or**l* J*v* S*, Or**l* *r**lVM *or J*K, Or**l* *r**lVM *nt*rpris* **ition pro*u*t o* Or**l* J*v* S* (*ompon*nt: *otspot). Support** v*rsions t**t *r* *****t** *r* Or**l* J*v* S*: *u***-p*r*, **.*.**, **.*.**, **.*.*, **.*.*; Or*

Reasoning

T** provi*** in*orm*tion *n* **t**** URL *ont*nts **s*ri** * vuln*r**ility (*V*-****-*****) in t** '*otspot' *ompon*nt o* Or**l* J*v* S*, Or**l* *r**lVM *or J*K, *n* Or**l* *r**lVM *nt*rpris* **ition. T** **s*ription st*t*s t**t t** vuln*r**ility **n