First published: Wed Dec 04 2019(Updated: )
IBM JDK 8 SR6 (8.0.6.0) fixes a flaw described by upstream as: Eclipse OpenJ9 could allow a local attacker to gain elevated privileges on the system, caused by the failure to performs an authorization check when an actor attempts to access a resource or perform an action. An attacker could exploit this vulnerability to gain access to diagnostic operations such as causing a GC or creating a diagnostic file. OpenJ9 upstream bug: <a href="https://bugs.eclipse.org/bugs/show_bug.cgi?id=552129">https://bugs.eclipse.org/bugs/show_bug.cgi?id=552129</a> References: <a href="https://www.ibm.com/support/pages/node/1120071">https://www.ibm.com/support/pages/node/1120071</a> <a href="https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBM_Security_Update_November_2019">https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBM_Security_Update_November_2019</a>
Affected Software | Affected Version | How to fix |
---|---|---|
IBM JDK 8 | ||
Eclipse OpenJ9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1779880 allows local attackers to gain elevated privileges due to insufficient authorization checks.
To fix REDHAT-BUG-1779880, update to IBM JDK 8 SR6 or later versions where the flaw is addressed.
REDHAT-BUG-1779880 affects IBM JDK 8 and Eclipse OpenJ9.
Local attackers can exploit REDHAT-BUG-1779880 to access unauthorized resources or perform restricted actions.
There are no known workarounds for REDHAT-BUG-1779880; the recommended action is to apply the necessary updates.