In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade java-1.8.0-ibm-srcUpgrade java-1.8.0-ibm-demoUpgrade java-1.8.0-ibm-webstartUpgrade java-1.8.0-ibm-develUpgrade java-1.8.0-ibm-headlessUpgrade java-1.8.0-ibmUpgrade java-1.8.0-ibm-jdbcUpgrade java-1.8.0-ibm-plugin | Sep 3, 2019 | Jul 17, 2019 |
| Ibm Aix | — | Apply the fix or workaround for java_july2019_advisory | Oct 11, 2019 | Jul 17, 2019 |
| Ibm Java | — | Upgrade IBM Java to version 8.0.5.40 | Aug 7, 2019 | Jul 17, 2019 |
| Redhat_linux | — | Upgrade java-1.8.0-ibm-srcUpgrade java-1.8.0-ibm-develUpgrade java-1.8.0-ibm-pluginUpgrade java-1.8.0-ibm-webstartUpgrade java-1.8.0-ibm-headlessUpgrade java-1.8.0-ibm-jdbcUpgrade java-1.8.0-ibmUpgrade java-1.8.0-ibm-demo | Sep 3, 2019 | Jul 17, 2019 |
| Suse | — | Upgrade java-1_8_0-ibm-pluginUpgrade java-1_8_0-ibmUpgrade java-1_8_0-ibm-alsaUpgrade java-1_8_0-ibm-devel | Sep 13, 2019 | Jul 17, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub