Oracle Family Security Update Advisory (CVE-2024-20932)

Overview

 

An update has been made available to fix vulnerabilities in the Oracle family of products. users of affected versions are advised to update to the latest version.

 

Affected Products

 

Oracle Java SE version 17.0.9

Oracle GraalVM for JDK version 17.0.9

Oracle GraalVM Enterprise Edition 21.3.8, 22.3.4 Versions

 

Resolved Vulnerabilities

 

Vulnerability that could allow unauthorized creation, deletion, or modification of accessible data by an attacker with network access via protocol (CVE-2024-20932)

 

Vulnerability Patches

 

Product-specific Vulnerability Patches were made available in the January 2024 Update. For more information on Vulnerability Patches, please refer to the “Affected Products and Patch Information” section of the Referenced Sites [2].

 

Referenced Sites

 

[1] CVE-2024-20932 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-20932
[2] Oracle Critical Patch Update Advisory – January 2024
https://www.oracle.com/security-alerts/cpujan2024.html