CVE-2025-50063
published 2025-07-15CVE-2025-50063: Vulnerability in Oracle Java SE (component: Install). The supported version that is affected is Oracle Java SE: 8u451. Easily exploitable vulnerability allows…
PriorityP337high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.24%
15.6th percentile
Vulnerability in Oracle Java SE (component: Install). The supported version that is affected is Oracle Java SE: 8u451. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Java SE executes to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE. Note: Applies to installation process on client deployment of Java. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | — | — |
| msrc | cbl2_kernel_5.15.173.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0 | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle_corporation | oracle_java_se | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
osv7.3HIGH
vendor_msrc7.8HIGH
vendor_debian7.3LOW
vendor_oracle7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Java SE Risk Matrix: Install — CVE-2025-50063
vendor_oracle·2025-07-15·CVSS 7.3
CVE-2025-50063 [HIGH] Oracle Oracle Java SE Risk Matrix: Install — CVE-2025-50063
Oracle Oracle Java SE Risk Matrix: Install vulnerability
CVE: CVE-2025-50063
CVSS: 7.3
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2025 (JUL 2025)
Debian
CVE-2025-50063: openjdk-8 - Vulnerability in Oracle Java SE (component: Install). The supported version th...
vendor_debian·2025·CVSS 7.3
CVE-2025-50063 [HIGH] CVE-2025-50063: openjdk-8 - Vulnerability in Oracle Java SE (component: Install). The supported version th...
Vulnerability in Oracle Java SE (component: Install). The supported version that is affected is Oracle Java SE: 8u451. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Java SE executes to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE. Note: Applies to installation process on client deployment of Java. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
Scope: local
sid: resolved
Microsoft
bpf: Prevent tail call between progs attached to different hooks
vendor_msrc·2024-10-08·CVSS 7.8
CVE-2024-50063 [HIGH] bpf: Prevent tail call between progs attached to different hooks
bpf: Prevent tail call between progs attached to different hooks
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: http
OSV
CVE-2025-50063: Vulnerability in Oracle Java SE (component: Install)
osv·2025-07-15·CVSS 7.3
CVE-2025-50063 [HIGH] CVE-2025-50063: Vulnerability in Oracle Java SE (component: Install)
Vulnerability in Oracle Java SE (component: Install). The supported version that is affected is Oracle Java SE: 8u451. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Java SE executes to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE. Note: Applies to installation process on client deployment of Java. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
GHSA
GHSA-x4mx-vv42-5h8p: Vulnerability in Oracle Java SE (component: Install)
ghsa_unreviewed·2025-07-15
CVE-2025-50063 [HIGH] GHSA-x4mx-vv42-5h8p: Vulnerability in Oracle Java SE (component: Install)
Vulnerability in Oracle Java SE (component: Install). Supported versions that are affected are Oracle Java SE: 8u451 and 8u451-perf. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Java SE executes to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE. Note: Applies to installation process on client deployment of Java. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-15
Published