First published: Fri Oct 11 2019(Updated: )
An out of bounds access flaw was found in the optimized implementation of String indexof() method for x86 platform in the Hotspot component of OpenJDK. This could cause Java Virtual Machine to crash or disclose limited information about the memory content.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <11-openjdk-1:11.0.5.10-0.el7_7 | 11-openjdk-1:11.0.5.10-0.el7_7 |
redhat/java | <11-openjdk-1:11.0.5.10-0.el8_0 | 11-openjdk-1:11.0.5.10-0.el8_0 |
debian/openjdk-11 | 11.0.24+8-2~deb11u1 11.0.25~5ea-1 | |
IBM Engineering Requirements Quality Assistant | <=All | |
Oracle OpenJDK 1.8.0 | =11.0.4 | |
Oracle OpenJDK 1.8.0 | =13.0.0 | |
Oracle JRE | =11.0.4 | |
Oracle JRE | =13.0.0 | |
NetApp Active IQ Unified Manager | >=7.3 | |
NetApp Active IQ Unified Manager for VMware vSphere | >=9.5 | |
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.50.2 | |
NetApp SANtricity Storage Manager | ||
NetApp SANtricity Unified Manager | ||
NetApp E-Series SANtricity Web Services | ||
NetApp OnCommand Workflow Automation | ||
NetApp SnapManager for Oracle | ||
NetApp SnapManager for SAP | ||
Debian | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Oracle Java SE vulnerability is CVE-2019-2977.
This vulnerability affects the Hotspot component of Oracle Java SE.
Java SE versions 11.0.4 and 13 are affected by this vulnerability.
An unauthenticated attacker with network access via multiple protocols can exploit this vulnerability.
The severity of CVE-2019-2977 is medium (4).
You can find more information about this vulnerability at the following references: [Oracle Security Alerts - CPUOct2019](https://www.oracle.com/security-alerts/cpuoct2019.html#AppendixJAVA) and [Red Hat Security Advisory - RHSA-2019:3127](https://access.redhat.com/errata/RHSA-2019:3127).