First published: Tue Nov 30 2021(Updated: )
IBM JDK 7 SR11 (7.0.11.0), 7.1 SR5 (7.1.5.0), and 8 SR7 (8.0.7.0) fix a flaw in OpenJ9 VM described by upstream as: In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods. References: <a href="https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities#IBM_Security_Update_November_2021">https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities#IBM_Security_Update_November_2021</a> <a href="https://bugs.eclipse.org/bugs/show_bug.cgi?id=576395">https://bugs.eclipse.org/bugs/show_bug.cgi?id=576395</a> <a href="https://github.com/eclipse-openj9/openj9/pull/13740">https://github.com/eclipse-openj9/openj9/pull/13740</a> <a href="https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/104">https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/104</a>
Affected Software | Affected Version | How to fix |
---|---|---|
IBM JDK 8 | ||
Eclipse Openj9 | <0.29.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity level of REDHAT-BUG-2027791 is considered high due to potential unauthorized access to inaccessible interface methods.
To fix REDHAT-BUG-2027791, update to IBM JDK 7 SR11, 7.1 SR5, or 8 SR7, or upgrade to a version of Eclipse OpenJ9 that is newer than 0.29.0.
REDHAT-BUG-2027791 affects IBM JDK versions 7.0.11.0, 7.1.5.0, and 8.0.7.0, along with Eclipse OpenJ9 versions prior to 0.29.0.
Yes, if exploited, REDHAT-BUG-2027791 can potentially lead to unauthorized access and data breaches.
No official workaround exists for REDHAT-BUG-2027791; the recommended action is to apply the necessary updates.