REDHAT-BUG-1779880: Medium severity ibm jdk 8 vulnerability
IBM JDK 8 SR6 (8.0.6.0) fixes a flaw described by upstream as:
Eclipse OpenJ9 could allow a local attacker to gain elevated privileges on the system, caused by the failure to performs an authorization check when an actor attempts to access a resource or perform an action. An attacker could exploit this vulnerability to gain access to diagnostic operations such as causing a GC or creating a diagnostic file.
OpenJ9 upstream bug:
https://bugs.eclipse.org/bugs/showbug.cgi?id=552129
References:
https://www.ibm.com/support/pages/node/1120071 https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBMSecurityUpdateNovember2019
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1779880?
The severity of REDHAT-BUG-1779880 allows local attackers to gain elevated privileges due to insufficient authorization checks.
How do I fix REDHAT-BUG-1779880?
To fix REDHAT-BUG-1779880, update to IBM JDK 8 SR6 or later versions where the flaw is addressed.
What products are affected by REDHAT-BUG-1779880?
REDHAT-BUG-1779880 affects IBM JDK 8 and Eclipse OpenJ9.
Who can exploit REDHAT-BUG-1779880?
Local attackers can exploit REDHAT-BUG-1779880 to access unauthorized resources or perform restricted actions.
Is there a workaround for REDHAT-BUG-1779880?
There are no known workarounds for REDHAT-BUG-1779880; the recommended action is to apply the necessary updates.