Skip to content
Threat Feed
high advisory

Multiple Vulnerabilities in Oracle GraalVM

Oracle GraalVM contains multiple vulnerabilities including CVE-2024-21226, CVE-2024-21227, and CVE-2024-21228, which allow remote unauthenticated attackers to compromise system confidentiality, integrity, and availability.

Oracle has disclosed multiple security vulnerabilities affecting various versions of Oracle GraalVM. These flaws permit a remote, unauthenticated attacker to execute arbitrary actions, potentially leading to a full compromise of the confidentiality, integrity, and availability of the host environment. The identified vulnerabilities, specifically CVE-2024-21226, CVE-2024-21227, and CVE-2024-21228, impact the Java runtime environment and associated components packaged within the GraalVM distribution. Because GraalVM is frequently deployed as a high-performance polyglot runtime in microservices and server-side applications, exploitation of these flaws could grant an attacker significant access to sensitive business logic, environment variables, or underlying cloud service identities. Organizations utilizing GraalVM for enterprise Java workloads should review their current build versions against the vendor-recommended patch levels to mitigate the risk of remote exploitation.

Impact

Successful exploitation of these vulnerabilities allows for unauthorized access and control over the affected system. This creates significant risks for organizations in the technology and financial sectors where Java-based runtimes are foundational to infrastructure. Compromise may result in unauthorized data exfiltration, system instability, or the ability for an attacker to pivot into internal network segments, causing potential widespread service disruption or permanent data loss if the runtime environment is not adequately isolated.

Recommendation

  1. Inventory all instances of Oracle GraalVM within the production environment, specifically targeting application servers and container images.
  2. Apply the latest security patches provided by Oracle for GraalVM to address CVE-2024-21226, CVE-2024-21227, and CVE-2024-21228.
  3. Ensure that containerized workloads are rebuilt using updated GraalVM base images to ensure the remediation is propagated across all microservices.
  4. Monitor outbound network traffic from Java runtime environments for anomalous connections that may indicate initial stages of exploitation or callback behavior.

Immediate actions

Patch GraalVM instances to address CVE-2024-21226, CVE-2024-21227, and CVE-2024-21228

IT Operations 48h

Mitigations

Upgrade Oracle GraalVM to the latest vendor-patched release

immediate IT Operations

CVE-2024-21226, CVE-2024-21227, CVE-2024-21228