First published: Mon Nov 11 2024(Updated: )
In Eclipse OpenJ9 versions up to 0.47, the JNI function GetStringUTFLength may return an incorrect value which has wrapped around. From 0.48 the value is correct but may be truncated to include a smaller number of characters.
Credit: emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse OpenJ9 | >=0.8.0<0.48.0 | |
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Software Stack | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Virtual Appliance | <=ISVG 10.0.2 | |
IBM Security Verify Governance Identity Manager Container | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10917 has not been assigned a specific CVSS score, but it can lead to incorrect value retrieval which may affect application stability.
To fix CVE-2024-10917, upgrade to Eclipse OpenJ9 version 0.48.0 or later where the issue is corrected.
CVE-2024-10917 affects Eclipse OpenJ9 versions from 0.8.0 up to 0.47.0.
CVE-2024-10917 may result in truncated string lengths being returned in JNI calls, potentially causing data inconsistency.
There are no known workarounds for CVE-2024-10917 other than upgrading to a secure version.