CVE-2025-30761
Oracle Java SE Scripting Data Tampering: stopped at runtime
Waratek RASP already blocks this exploit at runtime, inside the JVM - with no application change, no vendor patch, and no downtime.
Published July 15, 2025 · Updated June 17, 2026
The vulnerability
Unauthorized data modification via untrusted code in the Scripting component
A flaw in the Scripting component of Oracle Java SE and GraalVM Enterprise Edition lets an unauthenticated attacker with network access compromise the JVM, most commonly through a sandboxed Java Web Start application or applet that loads untrusted code from the internet. A successful attack lets the attacker create, delete, or modify data the JVM has access to, without needing any credentials.
Running an affected version? We can help.
Waratek RASP shields the vulnerable code in production - the exploit is blocked at runtime with no library upgrade, no redeploy, and no downtime. We can have you covered fast.
How Waratek RASP stops it
Blocked at runtime by Waratek RASP
Waratek RASP ships a patch rule that blocks exploitation at the exact point the dangerous operation is attempted, inside the JVM.
Runtime, not perimeter
Waratek RASP acts inside the JVM at the exact call that turns input into code, so obfuscated and encoded payloads are caught where a WAF misses them.
No code changes
Protection is applied as a rule at runtime. No source edits, no recompilation, no library upgrade, and no application restart required.
Zero false positives
Rules target the specific unsafe behaviour of the exploit, so legitimate traffic keeps flowing while the attack is blocked and logged.
| Mod | Rules | Enable |
|---|---|---|
| Oracle Java SE Scripting Data Tampering protectionCVE-2025-30761 · Unsafe deserialization | 1 | |
| SQL Injection protectionQuery manipulation | 4 | |
| Path Traversal protectionUnsafe file access | 3 |
Flip one toggle in the Waratek Portal. The protection deploys to every attached application, with no restart.
Common questions
Oracle Java SE Scripting Data Tampering FAQ
Is Oracle Java SE Scripting Data Tampering (CVE-2025-30761) exploitable?
CVE-2025-30761 carries a CVSS 5.9/10 (MEDIUM) rating and affects Oracle Java SE / Oracle GraalVM Enterprise Edition (Scripting component) 8u451 (and 8u451-perf) and 11.0.27, plus GraalVM Enterprise Edition 21.3.14. A flaw in the Scripting component of Oracle Java SE and GraalVM Enterprise Edition lets an unauthenticated attacker with network access compromise the JVM, most commonly through a sandboxed Java Web Start application or applet that loads untrusted code from the internet. A successful attack lets the attacker create, delete, or modify data the JVM has access to, without needing any credentials.
How does Waratek mitigate Oracle Java SE Scripting Data Tampering (CVE-2025-30761)?
Waratek RASP blocks exploitation of Oracle Java SE Scripting Data Tampering (CVE-2025-30761) inside the JVM at runtime, with no application code changes, no vendor patch and no restart.
Protect your apps in production
Get protected against Oracle Java SE Scripting Data Tampering - without code changes or redeploying
Book a call and we’ll show you how Waratek RASP shields your running applications against CVE-2025-30761 and attacks like it, and get you covered in production.