REDHAT-BUG-2027791: Medium severity ibm jdk 8 vulnerability
IBM JDK 7 SR11 (7.0.11.0), 7.1 SR5 (7.1.5.0), and 8 SR7 (8.0.7.0) fix a flaw in OpenJ9 VM described by upstream as:
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.
References:
https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities#IBMSecurityUpdateNovember2021 https://bugs.eclipse.org/bugs/showbug.cgi?id=576395 https://github.com/eclipse-openj9/openj9/pull/13740 https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/104
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2027791?
The severity level of REDHAT-BUG-2027791 is considered high due to potential unauthorized access to inaccessible interface methods.
How do I fix REDHAT-BUG-2027791?
To fix REDHAT-BUG-2027791, update to IBM JDK 7 SR11, 7.1 SR5, or 8 SR7, or upgrade to a version of Eclipse OpenJ9 that is newer than 0.29.0.
What products are affected by REDHAT-BUG-2027791?
REDHAT-BUG-2027791 affects IBM JDK versions 7.0.11.0, 7.1.5.0, and 8.0.7.0, along with Eclipse OpenJ9 versions prior to 0.29.0.
Can REDHAT-BUG-2027791 lead to data breaches?
Yes, if exploited, REDHAT-BUG-2027791 can potentially lead to unauthorized access and data breaches.
Is there a workaround for REDHAT-BUG-2027791?
No official workaround exists for REDHAT-BUG-2027791; the recommended action is to apply the necessary updates.