Severity: Medium
ID: 214522
File Name: oraclelinux_ELSA-2025-0422.nasl
Version: 1.1
Type: local
Agent: unix
Published: 1/23/2025
Updated: 1/23/2025
Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Nessus
Risk Factor: Medium
Score: 4.0
Risk Factor: Medium
Base Score: 4
Temporal Score: 3
Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:N
CVSS Score Source: CVE-2025-21502
Risk Factor: Medium
Base Score: 4.8
Temporal Score: 4.2
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
CPE: p-cpe:/a:oracle:linux:java-17-openjdk, p-cpe:/a:oracle:linux:java-17-openjdk-demo, p-cpe:/a:oracle:linux:java-17-openjdk-demo-fastdebug, p-cpe:/a:oracle:linux:java-17-openjdk-demo-slowdebug, p-cpe:/a:oracle:linux:java-17-openjdk-devel, p-cpe:/a:oracle:linux:java-17-openjdk-devel-fastdebug, p-cpe:/a:oracle:linux:java-17-openjdk-devel-slowdebug, p-cpe:/a:oracle:linux:java-17-openjdk-fastdebug, p-cpe:/a:oracle:linux:java-17-openjdk-headless, p-cpe:/a:oracle:linux:java-17-openjdk-headless-fastdebug, p-cpe:/a:oracle:linux:java-17-openjdk-headless-slowdebug, p-cpe:/a:oracle:linux:java-17-openjdk-javadoc, p-cpe:/a:oracle:linux:java-17-openjdk-javadoc-zip, p-cpe:/a:oracle:linux:java-17-openjdk-jmods, p-cpe:/a:oracle:linux:java-17-openjdk-jmods-fastdebug, p-cpe:/a:oracle:linux:java-17-openjdk-jmods-slowdebug, p-cpe:/a:oracle:linux:java-17-openjdk-slowdebug, p-cpe:/a:oracle:linux:java-17-openjdk-src, p-cpe:/a:oracle:linux:java-17-openjdk-src-fastdebug, p-cpe:/a:oracle:linux:java-17-openjdk-src-slowdebug, p-cpe:/a:oracle:linux:java-17-openjdk-static-libs, p-cpe:/a:oracle:linux:java-17-openjdk-static-libs-fastdebug, p-cpe:/a:oracle:linux:java-17-openjdk-static-libs-slowdebug, cpe:/o:oracle:linux:9, cpe:/a:oracle:linux:9::appstream, cpe:/a:oracle:linux:9::codeready_builder
Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/OracleLinux
Exploit Ease: No known exploits are available
Patch Publication Date: 1/22/2025
Vulnerability Publication Date: 1/21/2025
CVE: CVE-2025-21502