Improper input validation in Oracle GraalVM for JDK - CVE-2025-30761

 

Improper input validation in Oracle GraalVM for JDK - CVE-2025-30761

Published: July 16, 2025


Vulnerability identifier: #VU112940
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-30761
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The vulnerability exists due to improper input validation within the Scripting component in Oracle GraalVM for JDK. A remote non-authenticated attacker can exploit this vulnerability to manipulate data.


Affected software

Oracle GraalVM for JDK
Oracle Java SE
OpenJDK Java (for Middleware)
Rational Business Developer (RBD)
IBM Java SDK
IBM CICS TX Advanced
IBM CICS TX Standard
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
IBM i
Anolis OS
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Package Hub 15
Legacy Module
openSUSE Leap
Ubuntu
RSA Identity Governance and Lifecycle
SecurID Governance and Lifecycle
IBM Cloud Transformation Advisor
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Tivoli Monitoring
IBM Sterling External Authentication Server
IBM Tivoli Business Service Manager
IBM Sterling Connect:Direct Web Services
IBM Sterling Partner Engagement Manager
IBM Sterling Control Center
Communications Server for Linux on System z
Communications Server for Data Center Deployment
IBM Tivoli Netcool Impact
IBM Rational Build Forge
IBM Tivoli Netcool/OMNIbus WebGUI
Netcool/OMNIbus
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
WebSphere Service Registry and Repository
WebSphere eXtreme Scale
IBM Common Licensing
IBM Sterling Transformation Extender
IBM Robotic Process Automation
IBM Business Automation Workflow
IBM Tivoli System Automation Application Manager
IBM Sterling Connect:Direct for UNIX
Tivoli Composite Application Manager for Transactions
IBM SPSS Collaboration and Deployment Services
IBM Cloud Pak for Business Automation
SPSS Statistics
IBM WebSphere Application Server Patterns
SOAR App Host
PowerVM NovaLink
IBM OS Image for Red Hat Linux Systems
Tivoli Network Manager IP Edition
Cognos Dashboards on Cloud Pak for Data
IBM Sterling Connect:Direct for Microsoft Windows
Communications Server for Linux
Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines
Tivoli Monitoring for Virtual Environments Base
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Space Management
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
Rational Software Architect Designer (RSAD)
Rational Software Architect Designer for WebSphere Software
Verify Identity Access Digital Credentials
Robotic Process Automation for Cloud Pak
Business Automation Insights
Tivoli System Automation for Multiplatforms
Application Modernization Accelerator
IBM Semeru Runtimes
Storage Protect Server
Storage Protect Operations Center
Voice Gateway
IBM Cloud Pak System
IBM Tivoli Application Dependency Discovery Manager
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
java-1_8_0-ibm
java-1_8_0-ibm-plugin
java-1_8_0-ibm-alsa
java-1_8_0-ibm-devel
java-1_8_0-ibm-demo
java-1_8_0-ibm-src
java-1_8_0-ibm-devel-32bit
java-1_8_0-ibm-32bit
java-1.8.0-ibm-src (Red Hat package)
java-1.8.0-ibm-webstart (Red Hat package)
java-1.8.0-ibm-plugin (Red Hat package)
java-1.8.0-ibm-jdbc (Red Hat package)
java-1.8.0-ibm-headless (Red Hat package)
java-1.8.0-ibm-devel (Red Hat package)
java-1.8.0-ibm-demo (Red Hat package)
java-1.8.0-ibm (Red Hat package)
java-1.8.0-openjdk (Red Hat package)
java-1.8.0-openjdk-javadoc-zip
java-1.8.0-openjdk-javadoc
java-1.8.0-openjdk-src
java-1.8.0-openjdk-headless
java-1.8.0-openjdk-devel
java-1.8.0-openjdk-demo
java-1.8.0-openjdk-accessibility
java-1.8.0-openjdk
java-1_8_0-openjdk-debugsource
java-1_8_0-openjdk-headless-debuginfo
java-1_8_0-openjdk-demo
java-1_8_0-openjdk-debuginfo
java-1_8_0-openjdk-devel
java-1_8_0-openjdk
java-1_8_0-openjdk-devel-debuginfo
java-1_8_0-openjdk-demo-debuginfo
java-1_8_0-openjdk-headless
java-1_8_0-openjdk-accessibility
java-1_8_0-openjdk-src
java-1_8_0-openjdk-javadoc
java-1_8_0-openj9-accessibility
java-1_8_0-openj9-devel-debuginfo
java-1_8_0-openj9-debugsource
java-1_8_0-openj9
java-1_8_0-openj9-debuginfo
java-1_8_0-openj9-demo-debuginfo
java-1_8_0-openj9-headless
java-1_8_0-openj9-devel
java-1_8_0-openj9-demo
java-1_8_0-openj9-headless-debuginfo
java-1_8_0-openj9-javadoc
java-1_8_0-openj9-src
java-11-openjdk-demo
java-11-openjdk-headless
java-11-openjdk-devel
java-11-openjdk
java-11-openjdk-debugsource
java-11-openjdk-debuginfo
java-11-openjdk (Red Hat package)
java-11-openjdk-javadoc
java-11-openjdk-jmods
java-11-openjdk-devel-debuginfo
java-11-openjdk-headless-debuginfo
java-11-openjdk-src
openjdk-lts (Ubuntu package)
java-11-openjdk-static-libs
java-11-openjdk-javadoc-zip
IBM Security Verify Access
Event Streams
IBM Cognos Controller
Oracle GraalVM Enterprise Edition
IBM Security SOAR
IBM Cloud Pak for Multicloud Management
IBM Enterprise Content Management System Monitor

How to mitigate CVE-2025-30761

Install updates from vendor's website.

Voice Gateway - addressed in versions 1.0.8.17, 1.0.8.21
SOAR App Host - update to 1.15.6.1
PowerVM NovaLink - addressed in versions 2.1.1-251007, 2.2.1.1-251007, 2.3.1-251007
IBM Cloud Transformation Advisor - update to 4.4.0
IBM Cloud Pak System - update to 2.3.6.1
IBM OS Image for Red Hat Linux Systems - update to 4.0.8.0
IBM Decision Optimization for Cloud Pak for Data - update to 5.2.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.2.1
Cognos Dashboards on Cloud Pak for Data - update to 5.3
IBM Tivoli Monitoring - update to 6.3.0 FP7 Service Pack 6
IBM Sterling External Authentication Server - addressed in versions 6.1.0.3, 6.1.1.1
IBM Sterling Connect:Direct for Microsoft Windows - update to 6.2.0.8
IBM Sterling Connect:Direct Web Services - addressed in versions 6.2.0.29, 6.3.0.15, 6.4.0.4
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
IBM Sterling Control Center - addressed in versions 6.3.1.0.6, 6.4.1.0.1
IBM Tivoli Netcool Impact - update to 7.1.0.37
IBM Rational Build Forge - update to 8.0.0.30
OpenJDK Java (for Middleware) - addressed in versions 8.0.462, 11.0.28
Storage Protect Client - update to 8.2.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.0
Netcool/OMNIbus - update to 8.1.0.35
Storage Protect for Space Management - update to 8.2.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.29
WebSphere eXtreme Scale - update to 8.6.1.6 PH68541
IBM Common Licensing - update to 9.0.0.2
Event Streams - update to 12.2.0
IBM Cognos Controller - update to 11.0.1 FP7
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.4, 30.0.0.2
IBM Robotic Process Automation - addressed in versions 23.0.20.4, 30.0.0.2
Business Automation Insights - update to 25.0.0.0.1
IBM Security SOAR - update to 51.0.7.1
java-1_8_0-ibm - addressed in versions 1.8.0_sr8.50-30.138.1, 1.8.0_sr8.50-150000.3.104.1
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr8.50-30.138.1, 1.8.0_sr8.50-150000.3.104.1
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr8.50-30.138.1, 1.8.0_sr8.50-150000.3.104.1
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr8.50-30.138.1, 1.8.0_sr8.50-150000.3.104.1
java-1_8_0-ibm-demo - update to 1.8.0_sr8.50-150000.3.104.1
java-1_8_0-ibm-src - update to 1.8.0_sr8.50-150000.3.104.1
java-1_8_0-ibm-devel-32bit - update to 1.8.0_sr8.50-150000.3.104.1
java-1_8_0-ibm-32bit - update to 1.8.0_sr8.50-150000.3.104.1
java-1.8.0-ibm-src (Red Hat package) - update to 1.8.0.8.50-1.el8_10
java-1.8.0-ibm-webstart (Red Hat package) - update to 1.8.0.8.50-1.el8_10
java-1.8.0-ibm-plugin (Red Hat package) - update to 1.8.0.8.50-1.el8_10
java-1.8.0-ibm-jdbc (Red Hat package) - update to 1.8.0.8.50-1.el8_10
java-1.8.0-ibm-headless (Red Hat package) - update to 1.8.0.8.50-1.el8_10
java-1.8.0-ibm-devel (Red Hat package) - update to 1.8.0.8.50-1.el8_10
java-1.8.0-ibm-demo (Red Hat package) - update to 1.8.0.8.50-1.el8_10
java-1.8.0-ibm (Red Hat package) - update to 1.8.0.8.50-1.el8_10
java-1.8.0-openjdk (Red Hat package) - addressed in versions 1.8.0.462.b08-1.el7_9, 1.8.0.462.b08-1.el8_2, 1.8.0.462.b08-1.el8_4, 1.8.0.462.b08-1.el8_6, 1.8.0.462.b08-1.el9_0, 1.8.0.462.b08-2.el8, 1.8.0.462.b08-3.el9
java-1.8.0-openjdk-javadoc-zip - addressed in versions 1.8.0.462.b08-2.0.1, 1.8.0.472.b08-1
java-1.8.0-openjdk-javadoc - addressed in versions 1.8.0.462.b08-2.0.1, 1.8.0.472.b08-1
java-1.8.0-openjdk-src - addressed in versions 1.8.0.462.b08-2.0.1, 1.8.0.472.b08-1
java-1.8.0-openjdk-headless - addressed in versions 1.8.0.462.b08-2.0.1, 1.8.0.472.b08-1
java-1.8.0-openjdk-devel - addressed in versions 1.8.0.462.b08-2.0.1, 1.8.0.472.b08-1
java-1.8.0-openjdk-demo - addressed in versions 1.8.0.462.b08-2.0.1, 1.8.0.472.b08-1
java-1.8.0-openjdk-accessibility - addressed in versions 1.8.0.462.b08-2.0.1, 1.8.0.472.b08-1
java-1.8.0-openjdk - addressed in versions 1.8.0.462.b08-2.0.1, 1.8.0.472.b08-1
java-1_8_0-openjdk-debugsource - addressed in versions 1.8.0.462-27.117.1, 1.8.0.462-150000.3.109.1
java-1_8_0-openjdk-headless-debuginfo - addressed in versions 1.8.0.462-27.117.1, 1.8.0.462-150000.3.109.1
java-1_8_0-openjdk-demo - addressed in versions 1.8.0.462-27.117.1, 1.8.0.462-150000.3.109.1
java-1_8_0-openjdk-debuginfo - addressed in versions 1.8.0.462-27.117.1, 1.8.0.462-150000.3.109.1
java-1_8_0-openjdk-devel - addressed in versions 1.8.0.462-27.117.1, 1.8.0.462-150000.3.109.1
java-1_8_0-openjdk - addressed in versions 1.8.0.462-27.117.1, 1.8.0.462-150000.3.109.1
java-1_8_0-openjdk-devel-debuginfo - addressed in versions 1.8.0.462-27.117.1, 1.8.0.462-150000.3.109.1
java-1_8_0-openjdk-demo-debuginfo - addressed in versions 1.8.0.462-27.117.1, 1.8.0.462-150000.3.109.1
java-1_8_0-openjdk-headless - addressed in versions 1.8.0.462-27.117.1, 1.8.0.462-150000.3.109.1
java-1_8_0-openjdk-accessibility - update to 1.8.0.462-150000.3.109.1
java-1_8_0-openjdk-src - update to 1.8.0.462-150000.3.109.1
java-1_8_0-openjdk-javadoc - update to 1.8.0.462-150000.3.109.1
java-1_8_0-openj9-accessibility - update to 1.8.0.462-150200.3.57.1
java-1_8_0-openj9-devel-debuginfo - update to 1.8.0.462-150200.3.57.1
java-1_8_0-openj9-debugsource - update to 1.8.0.462-150200.3.57.1
java-1_8_0-openj9 - update to 1.8.0.462-150200.3.57.1
java-1_8_0-openj9-debuginfo - update to 1.8.0.462-150200.3.57.1
java-1_8_0-openj9-demo-debuginfo - update to 1.8.0.462-150200.3.57.1
java-1_8_0-openj9-headless - update to 1.8.0.462-150200.3.57.1
java-1_8_0-openj9-devel - update to 1.8.0.462-150200.3.57.1
java-1_8_0-openj9-demo - update to 1.8.0.462-150200.3.57.1
java-1_8_0-openj9-headless-debuginfo - update to 1.8.0.462-150200.3.57.1
java-1_8_0-openj9-javadoc - update to 1.8.0.462-150200.3.57.1
java-1_8_0-openj9-src - update to 1.8.0.462-150200.3.57.1
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12
IBM Tivoli System Automation Application Manager - addressed in versions 4.1.0.3.0.16, 4.1.0.4.0.13, 4.1.0.5.0.11, 4.1.0.6.0.5
Tivoli System Automation for Multiplatforms - addressed in versions 4.1.0.4.0.24, 4.1.0.5.0.18, 4.1.0.6.0.13, 4.1.0.7.0.13, 4.1.1.0.0.7, 4.1.1.1.0.8
Application Modernization Accelerator - update to 4.4.0
IBM Enterprise Content Management System Monitor - update to 5.7.000 FP1
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.2.0.9, 6.3.0.6, 6.4.0.3
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.26
IBM Java SDK - update to 8.0.8.50
IBM Semeru Runtimes - addressed in versions 8.0.462.0, 11.0.28.0, 17.0.16.0, 21.0.8.0
Storage Protect Server - update to 8.1.27.100
Storage Protect Operations Center - update to 8.2.0
IBM SPSS Collaboration and Deployment Services - update to 8.6.0.0.5
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix42, 11.1.0.0 ifix34
java-11-openjdk-demo - addressed in versions 11.0.28.0-3.90.1, 11.0.28.0-150000.3.129.2
java-11-openjdk-headless - addressed in versions 11.0.28.0-3.90.1, 11.0.28.0-150000.3.129.2
java-11-openjdk-devel - addressed in versions 11.0.28.0-3.90.1, 11.0.28.0-150000.3.129.2
java-11-openjdk - addressed in versions 11.0.28.0-3.90.1, 11.0.28.0-150000.3.129.2
java-11-openjdk-debugsource - addressed in versions 11.0.28.0-3.90.1, 11.0.28.0-150000.3.129.2
java-11-openjdk-debuginfo - addressed in versions 11.0.28.0-3.90.1, 11.0.28.0-150000.3.129.2
java-11-openjdk (Red Hat package) - addressed in versions 11.0.28.0.6-1.el7_9, 11.0.28.0.6-1.el8, 11.0.28.0.6-1.el9
java-11-openjdk-javadoc - update to 11.0.28.0-150000.3.129.2
java-11-openjdk-jmods - update to 11.0.28.0-150000.3.129.2
java-11-openjdk-devel-debuginfo - update to 11.0.28.0-150000.3.129.2
java-11-openjdk-headless-debuginfo - update to 11.0.28.0-150000.3.129.2
java-11-openjdk-src - update to 11.0.28.0-150000.3.129.2
openjdk-lts (Ubuntu package) - addressed in versions 11.0.28+6-1ubuntu1~18.04.1, 11.0.28+6-1ubuntu1~20.04.1, 11.0.28+6-1ubuntu1~22.04.1, 11.0.28+6-1ubuntu1~24.04.1, 11.0.28+6-1ubuntu1~25.04.1
java-11-openjdk-jmods - update to 11.0.29.0.7-1
java-11-openjdk-src - update to 11.0.29.0.7-1
java-11-openjdk - update to 11.0.29.0.7-1
java-11-openjdk-demo - update to 11.0.29.0.7-1
java-11-openjdk-devel - update to 11.0.29.0.7-1
java-11-openjdk-static-libs - update to 11.0.29.0.7-1
java-11-openjdk-headless - update to 11.0.29.0.7-1
java-11-openjdk-javadoc - update to 11.0.29.0.7-1
java-11-openjdk-javadoc-zip - update to 11.0.29.0.7-1
IBM CICS TX Standard - update to 11.1.0.0 ifix35
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001
SPSS Statistics - addressed in versions 27.0.1.0 IF033, 28.0.1.1 IF012, 28.0.1.1 IF015, 29.0.2.0 IF014, 29.0.2.0 IF016, 30.0.0.0 IF009, 30.0.0.0 IF0011, 31.0.0.0 IF001, 31.0.0.0 IF005

External References

Related Security Bulletins