JDK: Unrestricted access to diagnostic operations
Published Oct 17, 2019
9.1
CRITICALCVSS 3.1
EPSS 2.07%
Description
From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks.
Affected products
-
Affected
- 0.15 to 0.16 inclusive
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| The Eclipse Foundation | Eclipse OpenJ9 | unknown | Affected
|
Configuration 2
- 5.8
- 8.0
- 6.0
- 7.0
- 8.1
- 6.0
- 7.0
- 6.0
- 7.0
No data.
Red Hat Enterprise Linux 6 Supplementary
java-1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el6_10
Fixed · RHSA-2019:4113
Red Hat Enterprise Linux 7 Supplementary
java-1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el7
Fixed · RHSA-2019:4115
Red Hat Enterprise Linux 8
java-1.8.0-ibm-1:1.8.0.6.0-3.el8_1
Fixed · RHSA-2020:0046
Red Hat Satellite 5.8
java-1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el6_10
Fixed · RHSA-2020:0006
Red Hat Enterprise Linux 6
java-1.7.1-ibm
Not affected
Red Hat Enterprise Linux 7
java-1.7.1-ibm
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Supplementary | java-1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el6_10 | Fixed | RHSA-2019:4113 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el7 | Fixed | RHSA-2019:4115 |
| Red Hat Enterprise Linux 8 | java-1.8.0-ibm-1:1.8.0.6.0-3.el8_1 | Fixed | RHSA-2020:0046 |
| Red Hat Satellite 5.8 | java-1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el6_10 | Fixed | RHSA-2020:0006 |
| Red Hat Enterprise Linux 6 | java-1.7.1-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 7 | java-1.7.1-ibm | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/errata/RHSA-2019:4113 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4115 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0006 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0046 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-17631 Vendor Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=552129 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1779880 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-7944 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-17631
- https://www.cve.org/CVERecord?id=CVE-2019-17631
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2019:4113 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2019:4115 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2020:0006 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2020:0046 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-17631 | Vendor Advisory | |
| https://bugs.eclipse.org/bugs/show_bug.cgi?id=552129 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1779880 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-7944 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-17631 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-17631 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data