First published: Mon Oct 25 2021(Updated: )
Eclipse Openj9 could allow a remote attacker to gain elevated privileges on the system, caused by not throwing IllegalAccessError for MethodHandles that invoke inaccessible interface methods. By persuading a victim to execute a specially-crafted program under a security manager, an attacker could exploit this vulnerability to gain elevated privileges and execute arbitrary code on the system.
Credit: emo@eclipse.org emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.8.0-ibm-1:1.8.0.7.0-1jpp.1.el7 | 1.8.0-ibm-1:1.8.0.7.0-1jpp.1.el7 |
redhat/java | <1.7.1-ibm-1:1.7.1.5.0-1jpp.1.el7 | 1.7.1-ibm-1:1.7.1.5.0-1jpp.1.el7 |
redhat/java | <1.8.0-ibm-1:1.8.0.7.0-1.el8_5 | 1.8.0-ibm-1:1.8.0.7.0-1.el8_5 |
Eclipse Openj9 | <0.29.0 | |
IBM Cognos Analytics | <=12.0.0-12.0.1 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP2 | |
IBM Cognos Analytics | <=11.1.1-11.1.7 FP7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-41035 is a vulnerability in Eclipse Openj9 that allows a remote attacker to gain elevated privileges on the system.
CVE-2021-41035 has a severity score of 7.7, indicating a high severity.
The affected software includes Eclipse Openj9 versions before 0.29.0.
To fix CVE-2021-41035, update Eclipse Openj9 to version 0.29.0 or later.
You can find more information about CVE-2021-41035 at the following references: [link1], [link2], [link3].