CVE-2025-50063

Publication date 15 July 2025

Last updated 23 July 2025


Ubuntu priority

Cvss 3 Severity Score

7.3 · High

Score breakdown

Vulnerability in Oracle Java SE (component: Install). The supported version that is affected is Oracle Java SE: 8u451. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Java SE executes to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE. Note: Applies to installation process on client deployment of Java. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).

Status

Package Ubuntu Release Status
openjdk-8 25.04 plucky
Not affected
24.04 LTS noble
Not affected
22.04 LTS jammy
Not affected
20.04 LTS focal
Not affected
18.04 LTS bionic
Not affected
16.04 LTS xenial
Not affected
openjdk-9 25.04 plucky Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
16.04 LTS xenial Ignored no longer supported by upstream
openjdk-lts 25.04 plucky
Needs evaluation
24.04 LTS noble
Needs evaluation
22.04 LTS jammy
Needs evaluation
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
openjdk-13 25.04 plucky Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
20.04 LTS focal Ignored superseded by openjdk-17
openjdk-16 25.04 plucky Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
20.04 LTS focal Ignored superseded by openjdk-17
openjdk-17 25.04 plucky
Needs evaluation
24.04 LTS noble
Needs evaluation
22.04 LTS jammy
Needs evaluation
18.04 LTS bionic
Needs evaluation
openjdk-17-crac 25.04 plucky
Needs evaluation
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
openjdk-18 25.04 plucky Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Ignored superseded by openjdk-19
openjdk-19 25.04 plucky Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Ignored no longer supported by upstream
openjdk-21 25.04 plucky
Needs evaluation
24.04 LTS noble
Needs evaluation
22.04 LTS jammy
Needs evaluation
openjdk-21-crac 25.04 plucky
Needs evaluation
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
openjdk-24 25.04 plucky
Needs evaluation
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
openjdk-25 25.04 plucky
Needs evaluation
24.04 LTS noble Not in release
22.04 LTS jammy Not in release

Severity score breakdown

Parameter Value
Base score 7.3 · High
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction Required
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H