Appsecure logo

CVE-2023-22067: Medium Vulnerability in Oracle Java SE & Oracle GraalVM Enterprise Edition

A medium-severity vulnerability in Oracle Java SE and GraalVM Enterprise Edition allows unauthenticated attackers to compromise data via CORBA. Organizations should prioritize patching to mitigate risks.

MEDIUMCVSS 5.3 · Published October 17, 2023

Not a customer? See how AppSecure simulates real world attacks to protect your infrastructure.

Speak to Experts

CVE-2023-22067 is a medium-severity vulnerability affecting Oracle Java SE and Oracle GraalVM Enterprise Edition. The vulnerability exists in the CORBA component and is present in supported versions of Oracle Java SE: 8u381 and 8u381-perf, as well as Oracle GraalVM Enterprise Edition: 20.3.11 and 21.3.7. This vulnerability allows an unauthenticated attacker with network access via CORBA to compromise the affected systems.

Successful exploitation of this vulnerability could lead to unauthorized update, insertion, or deletion of some accessible data within Oracle Java SE and Oracle GraalVM Enterprise Edition. The attack does not require user interaction, and the vulnerability can be exploited by supplying data to APIs in the specified component without the need for untrusted Java Web Start applications or untrusted Java applets.

The CVSS 3.1 base score for this vulnerability is 5.3, indicating a medium severity level. The CVSS vector indicates a network attack vector with low complexity and no required privileges or user interaction. Organizations should prioritize patching immediately to mitigate the risks associated with this vulnerability.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Latest CVEs. Recently published vulnerabilities from the NVD database.

View all vulnerabilities
CVE IDSeverity
CVE-2025-65418HIGH
CVE-2025-65417MEDIUM
CVE-2025-65416MEDIUM
CVE-2025-65415MEDIUM
CVE-2025-61314HIGH

Protect Your Business with Hacker-Focused Approach.