CVE Database
/

CVE-2019-11772

Back to search

CVE-2019-11772

Published: Jul 17, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.

VendorProductVersions

The Eclipse Foundation

Eclipse OpenJ9

affected
unspecified - < 0.15.0

Weaknesses (CWE)

References

RHSA-2019:2585
vendor-advisory
x_refsource_REDHAT
RHSA-2019:2590
vendor-advisory
x_refsource_REDHAT
RHSA-2019:2592
vendor-advisory
x_refsource_REDHAT
RHSA-2019:2737
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now