Vulnerability record · CVE-2022-21449 · published 19 April 2022
CVE-2022-21449: Oracle Java SE and GraalVM signature verification flaw allows data tampering
Oracle · Graalvm
A vulnerability in the Libraries component of Oracle Java SE (17.0.2, 18) and Oracle GraalVM Enterprise Edition (21.3.1, 22.0.0.2) allows an unauthenticated network attacker to compromise the product. Successful exploitation can result in unauthorized creation, deletion, or modification access to critical data or all accessible data. The flaw is easily exploitable and applies to Java deployments that load and run untrusted code, such as sandboxed Web Start applications or applets, and to APIs supplied data by web services.
Description
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.2 and 18; Oracle GraalVM Enterprise Edition: 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Automated analysis
high priorityCVSS 7.5 with network reachability, no authentication, no user interaction, and a very high EPSS percentile (99.098) indicate significant exploitation likelihood despite no KEV listing.
What it is
A vulnerability in the Libraries component of Oracle Java SE (17.0.2, 18) and Oracle GraalVM Enterprise Edition (21.3.1, 22.0.0.2) allows an unauthenticated network attacker to compromise the product. Successful exploitation can result in unauthorized creation, deletion, or modification access to critical data or all accessible data. The flaw is easily exploitable and applies to Java deployments that load and run untrusted code, such as sandboxed Web Start applications or applets, and to APIs supplied data by web services.
Impact
An attacker gains unauthorized integrity impact, able to create, delete, or modify critical data or all data accessible to the affected Java SE or GraalVM instance. There is no confidentiality or availability impact per the CVSS vector.
Attack surface
Reachable over the network via multiple protocols with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). It can be triggered through sandboxed Java Web Start applications, applets loading untrusted code, or APIs in the affected component that receive data from a web service.
Exploitation
Not listed in CISA KEV and no ransomware groups are documented using it. EPSS probability is 0.60336 (99.098th percentile), indicating a high likelihood of exploitation activity, and references are primarily mailing list and third-party advisories with a vendor patch advisory.
What to do
- Apply the Oracle Critical Patch Update (April 2022) or later for Java SE and GraalVM Enterprise Edition.
- Upgrade to fixed Java SE and GraalVM versions; affected versions are Java SE 17.0.2 and 18, and GraalVM Enterprise Edition 21.3.1 and 22.0.0.2.
- Apply vendor patches from Debian (DSA-5128, DSA-5131) and NetApp advisories for affected products.
- Disable or restrict sandboxed Java Web Start applications and applets that load untrusted code where not required.
- Review and restrict network exposure of services and APIs that accept data into the affected Java Libraries component.
Detection
- Monitor for exploitation attempts against Java SE and GraalVM services that accept untrusted data over the network.
- Audit Java deployments for affected versions (17.0.2, 18, GraalVM 21.3.1, 22.0.0.2) and verify patch status.
- Review application logs for unexpected data creation, deletion, or modification events in Java-based services.
- Track EPSS and vendor advisories for updated exploitation signals, since KEV does not list this CVE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-21449 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-21449), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.