First published: Fri Oct 11 2019(Updated: )
An out of bounds access flaw was found in the optimized implementation of String indexof() method for x86 platform in the Hotspot component of OpenJDK. This could cause Java Virtual Machine to crash or disclose limited information about the memory content.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <11-openjdk-1:11.0.5.10-0.el7_7 | 11-openjdk-1:11.0.5.10-0.el7_7 |
redhat/java | <11-openjdk-1:11.0.5.10-0.el8_0 | 11-openjdk-1:11.0.5.10-0.el8_0 |
Oracle JDK | =11.0.4 | |
Oracle JDK | =13.0.0 | |
Oracle JRE | =11.0.4 | |
Oracle JRE | =13.0.0 | |
Netapp Active Iq Unified Manager Windows | >=7.3 | |
Netapp Active Iq Unified Manager Vmware Vsphere | >=9.5 | |
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.50.2 | |
Netapp E-series Santricity Storage Manager | ||
Netapp E-series Santricity Unified Manager | ||
Netapp E-series Santricity Web Services Proxy | ||
NetApp OnCommand Workflow Automation | ||
Netapp Snapmanager Oracle | ||
Netapp Snapmanager Sap | ||
Debian Debian Linux | =10.0 | |
IBM Engineering Requirements Quality Assistant On-Premises | <=All | |
debian/openjdk-11 | 11.0.24+8-2~deb11u1 11.0.25~5ea-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Oracle Java SE vulnerability is CVE-2019-2977.
This vulnerability affects the Hotspot component of Oracle Java SE.
Java SE versions 11.0.4 and 13 are affected by this vulnerability.
An unauthenticated attacker with network access via multiple protocols can exploit this vulnerability.
The severity of CVE-2019-2977 is medium (4).
You can find more information about this vulnerability at the following references: [Oracle Security Alerts - CPUOct2019](https://www.oracle.com/security-alerts/cpuoct2019.html#AppendixJAVA) and [Red Hat Security Advisory - RHSA-2019:3127](https://access.redhat.com/errata/RHSA-2019:3127).