CVE-2025-21587

Oracle Java SE JSSE Compromise: stopped at runtime

Waratek RASP already blocks this exploit at runtime, inside the JVM - with no application change, no vendor patch, and no downtime.

Published April 15, 2025 · Updated June 17, 2026

Mitigated by Waratek HIGH CVSS 7.4 v3.1

The vulnerability

Full data compromise via unauthenticated network exploitation of JSSE

A flaw in the JSSE component of Oracle Java SE and GraalVM lets an unauthenticated attacker with network access, over multiple protocols, compromise the JVM through APIs exposed in that component. Oracle rates it difficult to exploit, but a successful attack grants full read and write access to all data the JVM can reach, making it a critical patch-cadence item for any internet-facing Java service.

Affected softwareOracle Java SE / Oracle GraalVM (JSSE component)
Affected versions8u441 (and 8u441-perf), 11.0.26, 17.0.14, 21.0.6, 24, plus affected GraalVM for JDK and GraalVM Enterprise Edition builds
WeaknessImproper access control (CWE-284)
Published2025-04-15
SeverityHIGH · CVSS 7.4

Running an affected version? We can help.

Waratek RASP shields the vulnerable code in production - the exploit is blocked at runtime with no library upgrade, no redeploy, and no downtime. We can have you covered fast.

Talk to us about protection

How Waratek RASP stops it

Blocked at runtime by Waratek RASP

Waratek RASP ships a patch rule that blocks exploitation at the exact point the dangerous operation is attempted, inside the JVM.

Runtime, not perimeter

Waratek RASP acts inside the JVM at the exact call that turns input into code, so obfuscated and encoded payloads are caught where a WAF misses them.

No code changes

Protection is applied as a rule at runtime. No source edits, no recompilation, no library upgrade, and no application restart required.

Zero false positives

Rules target the specific unsafe behaviour of the exploit, so legitimate traffic keeps flowing while the attack is blocked and logged.

Flip one toggle in the Waratek Portal. The protection deploys to every attached application, with no restart.

Common questions

Oracle Java SE JSSE Compromise FAQ

Is Oracle Java SE JSSE Compromise (CVE-2025-21587) exploitable?

CVE-2025-21587 carries a CVSS 7.4/10 (HIGH) rating and affects Oracle Java SE / Oracle GraalVM (JSSE component) 8u441 (and 8u441-perf), 11.0.26, 17.0.14, 21.0.6, 24, plus affected GraalVM for JDK and GraalVM Enterprise Edition builds. A flaw in the JSSE component of Oracle Java SE and GraalVM lets an unauthenticated attacker with network access, over multiple protocols, compromise the JVM through APIs exposed in that component. Oracle rates it difficult to exploit, but a successful attack grants full read and write access to all data the JVM can reach, making it a critical patch-cadence item for any internet-facing Java service.

How does Waratek mitigate Oracle Java SE JSSE Compromise (CVE-2025-21587)?

Waratek RASP blocks exploitation of Oracle Java SE JSSE Compromise (CVE-2025-21587) inside the JVM at runtime, with no application code changes, no vendor patch and no restart.

Protect your apps in production

Get protected against Oracle Java SE JSSE Compromise - without code changes or redeploying

Book a call and we’ll show you how Waratek RASP shields your running applications against CVE-2025-21587 and attacks like it, and get you covered in production.