First published: Wed Aug 05 2020(Updated: )
IBM JDK 7 SR10 FP70 (7.0.10.70), 7.1 SR4 FP70 (7.1.4.70), and 8 SR6 FP15 (8.0.6.15) fix a flaw described by upstream as: Eclipse OpenJ9 could allow a remote attacker to obtain sensitive information, caused by the premature return of the current method with an undefined return value. By invoking the System.arraycopy method with a length longer than the length of the source or destination array can, an attacker could exploit this vulnerability to obtain sensitive information. IBM also notes that this issue is only applicable to IBM JDK on AIX and Linux on the Power platform. OpenJ9 upstream bug: <a href="https://bugs.eclipse.org/bugs/show_bug.cgi?id=563998">https://bugs.eclipse.org/bugs/show_bug.cgi?id=563998</a> References: <a href="https://www.ibm.com/support/pages/node/6256562">https://www.ibm.com/support/pages/node/6256562</a> <a href="https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBM_Security_Update_August_2020">https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBM_Security_Update_August_2020</a>
Affected Software | Affected Version | How to fix |
---|---|---|
IBM JDK 8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1866497 is classified as high due to the potential for remote attackers to obtain sensitive information.
To fix REDHAT-BUG-1866497, upgrade to IBM JDK 7 SR10 FP70, 7.1 SR4 FP70, or 8 SR6 FP15.
IBM JDK 7 SR10 FP70, 7.1 SR4 FP70, and 8 SR6 FP15 are impacted by REDHAT-BUG-1866497.
REHAT-BUG-1866497 is a vulnerability that allows sensitive information leakage through undefined return values in methods.
Organizations using affected versions of IBM JDK should be concerned about REDHAT-BUG-1866497 and take necessary steps to mitigate the risk.