Advisory Published
Updated

REDHAT-BUG-2108543

First published: Tue Jul 19 2022(Updated: )

It was discovered that the Hotspot component of OpenJDK did not properly restrict access to the invokeBasic() method of the MethodHandle class. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.

Affected SoftwareAffected VersionHow to fix
Microsoft Build of OpenJDK with Hotspot

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Reference Links

Frequently Asked Questions

  • What is the severity of REDHAT-BUG-2108543?

    REDHAT-BUG-2108543 is considered a critical vulnerability because it allows untrusted applications to bypass Java sandbox restrictions.

  • How do I fix REDHAT-BUG-2108543?

    To fix REDHAT-BUG-2108543, update OpenJDK Hotspot to the latest patched version that addresses this vulnerability.

  • Which versions of OpenJDK Hotspot are affected by REDHAT-BUG-2108543?

    REDHAT-BUG-2108543 affects multiple versions of OpenJDK Hotspot, specifically those that do not implement proper restrictions on the invokeBasic() method.

  • Can REDHAT-BUG-2108543 lead to remote code execution?

    Yes, REDHAT-BUG-2108543 can potentially allow an attacker to execute arbitrary code on a user's machine by bypassing the Java sandbox.

  • Is it safe to run untrusted Java applications with REDHAT-BUG-2108543 present?

    No, running untrusted Java applications with REDHAT-BUG-2108543 present poses significant security risks due to the vulnerability's ability to circumvent safety measures.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203