Improper input validation in Oracle Java SE - CVE-2025-0509
Published: January 21, 2025
Vulnerability identifier: #VU103158
CSH Severity: Medium
CVSS v4: 5.4 [CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-0509
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Install (Sparkle) component in Oracle Java SE. A remote privileged user can exploit this vulnerability to execute arbitrary code.
Affected software
Oracle Java SE
Integrated Data protection Appliance (IDPA)
Data Protection Search
Storage Resource Manager
Dell EMC Storage Monitoring and Reporting (SMR)
Integrated Data protection Appliance (IDPA)
Data Protection Search
Storage Resource Manager
Dell EMC Storage Monitoring and Reporting (SMR)
How to mitigate CVE-2025-0509
Install updates from vendor's website.
Integrated Data protection Appliance (IDPA) - update to 2.7.8 with DP Search 19.6.6
Storage Resource Manager - addressed in versions 5.0.2.2, 5.1.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 5.0.2.2, 5.1.0.0
Data Protection Search - update to 19.6.6
Storage Resource Manager - addressed in versions 5.0.2.2, 5.1.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 5.0.2.2, 5.1.0.0
Data Protection Search - update to 19.6.6
External References
Related Security Bulletins
- Multiple vulnerabilities in Oracle Java SE
- Multiple vulnerabilities in Dell Data Protection Search
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)