First published: Wed Aug 07 2019(Updated: )
IBM JDK 7 SR10 FP50 (7.0.10.50), 7.1 SR4 FP50 (7.1.4.50), and 8 SR5 FP40 (8.0.5.40) fix a flaw described by upstream as: Eclipse OpenJ9 could allow a local attacker to gain elevated privileges on the system, caused by an error where the loop versioner fails to privatize a value that is pulled out of the loop by versioning. An attacker could exploit this vulnerability to corrupt memory and trigger an out-of-array-bounds and perform invalid actions. OpenJ9 upstream bug: <a href="https://bugs.eclipse.org/bugs/show_bug.cgi?id=549601">https://bugs.eclipse.org/bugs/show_bug.cgi?id=549601</a> Eclipse OMR upstream bug and merge request: <a href="https://bugs.eclipse.org/bugs/show_bug.cgi?id=549192">https://bugs.eclipse.org/bugs/show_bug.cgi?id=549192</a> <a href="https://github.com/eclipse/omr/pull/4138">https://github.com/eclipse/omr/pull/4138</a> References: <a href="https://www-01.ibm.com/support/docview.wss?uid=ibm10960422">https://www-01.ibm.com/support/docview.wss?uid=ibm10960422</a> <a href="https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBM_Security_Update_July_2019">https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBM_Security_Update_July_2019</a>
Affected Software | Affected Version | How to fix |
---|---|---|
IBM JDK 8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-1738549 is classified as a privilege escalation vulnerability.
To fix REDHAT-BUG-1738549, update to IBM JDK 7 SR10 FP50, 7.1 SR4 FP50, or 8 SR5 FP40.
Users of IBM JDK versions 7 and 8 are affected by REDHAT-BUG-1738549.
Systems running affected versions of IBM JDK are vulnerable to REDHAT-BUG-1738549.
There is no documented workaround for REDHAT-BUG-1738549; the recommended action is to apply the update.